Impact
IDOR allowing a user (e.g. with Service desk agent profile) to create a ModuleInstallation object, while he shouldn't be able to do it.
References
- Combodo N°8198 - [SECU] IDOR with ModuleInstallation object
Credits
Thanks to Sabastiaz
For more information
If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com
Impact
IDOR allowing a user (e.g. with Service desk agent profile) to create a ModuleInstallation object, while he shouldn't be able to do it.
References
Credits
Thanks to Sabastiaz
For more information
If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com