Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 2025.01
affected
Description
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelectionNetworks.asp.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version before 2025.01
Credits
Oscar Atienza
References
www.incibe.es/...ulnerabilities-dm-corporative-cms-dmacroweb