dataCycle-CORE
- <= 25.07.3
A vulnerability exists in dataCycle-CORE versions prior to 25.07.3, allowing authenticated API users to impersonate other users and access their collections. This is achieved by supplying a target user's email to the collection API, which can then expose those collections if they exist. Furthermore, in version 4, once a collection ID is obtained, the same API controller provides routes to add or remove items from the collection without proper authorization checks, potentially allowing cross-user modifications.
Exploitation of this vulnerability could lead to unauthorized access to user collections via the API, and in version 4, could allow for unauthorized modifications to those collections by adding or removing items.
Users can upgrade to dataCycle-CORE version 26.06.08 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.