GN4 Publishing System Insecure Direct Object Reference Vulnerability Allowing Information Disclosure
Vulnerability
A vulnerability allowing insecure direct object reference (IDOR) has been identified in GN4 Publishing System versions prior to 2.6. This vulnerability exists within the API, where authenticated users can make requests to object endpoints and access sensitive account information by specifying arbitrary user IDs. The exposed data includes the user's stored password, security question and answer, which could be used to reset or take over the account.
Impact
Exploitation of this vulnerability allows for unauthorized access to sensitive account information, including passwords and answers to security questions, which could be used to reset or take over user accounts.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
