An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-06-09T15:14:10

Updated: 2022-06-09T15:14:10

Reserved: 2022-05-16T00:00:00


Link: CVE-2022-30760

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-06-09T16:15:08.870

Modified: 2022-06-17T19:57:09.527


Link: CVE-2022-30760

JSON object: View

cve-icon Redhat Information

No data.

CWE