LitmusChaos Insecure Direct Object Reference Vulnerability in Project Access Control

Vulnerability

A critical Insecure Direct Object Reference (IDOR) vulnerability exists in LitmusChaos versions through 3.19.0. This vulnerability allows low-privileged users to access sensitive information from projects belonging to other users by manipulating the projectID parameter in the URL. The application fails to properly validate user permissions before granting access to project data, leading to unauthorized disclosure of internal project information.

Impact

Exploitation of this vulnerability allows authenticated users to access confidential project metadata of other users, resulting in unauthorized data exposure, enumeration of internal user roles, emails, or team structures, and potential reconnaissance for further privilege escalation or social engineering attacks.

Reproduction

To reproduce this vulnerability, log in as a user with access to a project. While navigating the platform, observe the projectID in the URL. Replace this ID with the projectID of another user’s project and refresh the page. The sensitive information from the other user’s project will be displayed, confirming the access control flaw.

Added: Aug 10, 2025, 4:17 AM
Updated: Aug 10, 2025, 4:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.2
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.