← Back

CVE-2024-25270

nvd nist
Published: Sep 12, 2024Modified: Mar 25, 2025

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.

Affected (1)

Products: Mirapolis: Lms
1 product
Lms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 4.6.00

References (1)

Source: cve@mitre.org
Third Party Advisory

Timeline

No history available yet.