CVE-2024-25270

An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.
References
Link Resource
https://github.com/fbkcs/CVE-2024-25270 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mirapolis:lms:*:*:*:*:*:*:*:*

History

13 Sep 2024, 16:01

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-12 19:15

Updated : 2025-03-25 17:15


NVD link : CVE-2024-25270

Mitre link : CVE-2024-25270

CVE.ORG link : CVE-2024-25270


JSON object : View

Products Affected

mirapolis

  • lms
CWE
CWE-639

Authorization Bypass Through User-Controlled Key