Cisco Slido Insecure Direct Object Reference Vulnerability
Vulnerability
A vulnerability exists in the REST API of Cisco Slido, allowing authenticated, remote attackers to access the social profile data of other users or manipulate quiz and poll results. This issue arises from an insecure direct object reference, enabling attackers to send crafted requests to the vulnerable API endpoint. Exploitation could lead to unauthorized access to user social profiles or interference with quiz and poll outcomes.
Impact
Exploitation of this vulnerability could result in unauthorized access to social profile data of users or manipulation of quiz and poll results.
Added: May 6, 2026, 6:37 PM
Updated: May 6, 2026, 6:37 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.3exploitability
5.2remediation
0.0relevance
7.6threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
