BOLD Workplanner Insecure Direct Object Reference Vulnerability
Vulnerability
An Insecure Direct Object Reference (IDOR) vulnerability has been identified in BOLD Workplanner by Global Planning Solutions (GPS), affecting versions prior to 2.5.25. This vulnerability arises from insufficient validation of user input, allowing authenticated users to access basic employee details, such as names, national identity numbers, and attendance records, using unauthorized internal identifiers.
Impact
Exploitation of this vulnerability allows unauthorized access to sensitive employee information, including personal details and attendance records, through the use of internal identifiers that should not be accessible to the user.
Remediation
Users can upgrade to BOLD Workplanner version 2.5.25 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
