Customer Portal IDOR Vulnerability in Access Control

Vulnerability

A vulnerability allowing Insecure Direct Object References (IDOR) has been identified in the access control of Customer Portal versions prior to 2.1.4. This vulnerability allows attackers to manipulate request parameters or object references to gain unauthorized access.

Impact

Exploitation of this vulnerability could lead to unauthorized access to objects or resources within the application, bypassing normal access controls.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.8
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.