Fullstep V5 Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing insecure direct object reference (IDOR) has been identified in the Fullstep V5 registration process. This vulnerability allows authenticated users to access data belonging to other registered users through various authenticated resources in the application. The issue arises in endpoints that list user information and those that allow users to update their personal details and documents.

Impact

Exploitation of this vulnerability could lead to unauthorized access to and modification of other users' data.

Remediation

The vulnerability has been fixed in Fullstep version 5.30.07, which has been available in production since January 29, 2026.

Added: Apr 22, 2026, 2:21 PM
Updated: Apr 22, 2026, 2:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
5.2
remediation
0.0
relevance
6.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.