Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating the id parameter.
This Cyber News was published on www.tenable.com. Publication date: Fri, 20 Dec 2024 20:56:02 +0000