Description
An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.
Problem types
CWE-639: Authorization Bypass Through User-Controlled Key
Product status
Any version
Credits
Thank you to [Kacper Leszczyński / szotgan](https://gitlab.com/szotgan) on GitLab for reporting this issue.
References
gitlab.com/crafty-controller/crafty-4/-/work_items/705
gitlab.com/crafty-controller/crafty-4/-/work_items/705