BOLD Workplanner Insecure Direct Object Reference Vulnerability
Vulnerability
An Insecure Direct Object Reference (IDOR) vulnerability has been identified in BOLD Workplanner by Global Planning Solutions (GPS), affecting versions prior to 2.5.25. This vulnerability arises from inadequate validation of user input, allowing authenticated users to access sensitive information such as employee details and permissions using unauthorized internal identifiers.
Impact
Exploitation of this vulnerability allows unauthorized access to the list of permissions and other sensitive employee information using internal identifiers that should not be accessible.
Remediation
Users can upgrade to BOLD Workplanner version 2.5.25 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
