Description
Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user account, such as changing the victim's email address, validating the new email address, and requesting a new password. This could allow them to take complete control of other users' legitimate accounts
Problem types
CWE-639 Authorization bypass through User-Controlled key
Product status
all versions
References
www.incibe.es/...iple-vulnerabilities-wakyma-application-web