Description


A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insecure direct object references. This could lead to unauthorized access to sensitive information and unauthorized changes to the tenant's configuration.

Related CPE's


References


Weaknesses



CWE-639

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

6.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-04-22T14:17:06.627Z

5 months ago

Last modified

2026-06-17T11:00:42.547Z

3 months ago