We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by making a POST request and modifying the “pkrelated” parameter in the “/h6web/ha_datos_hermano.php” endpoint to refer to another user. In addition, the first request could also allow the attacker to impersonate other users. As a result, all requests made after exploitation of the IDOR vulnerability will be executed with the privileges of the impersonated user.
Reserved 2025-02-13 | Published 2025-02-13 | Updated 2025-02-13 | Assigner INCIBECWE-639 Authorization Bypass Through User-Controlled Key
Bertrand Lorente Yáñez
www.incibe.es/.../multiple-vulnerabilities-anapi-group-h6web
Support options