All CosmicBytez Labs articles tagged #IDOR, across news, security advisories, how-to guides, and projects.
A critical CVSS 9.1 vulnerability in SolarWinds Serv-U allows group administrators to exploit an insecure direct object reference flaw to escalate...
A critical IDOR vulnerability in Coolify's cloneTo() Livewire action allows authenticated users to clone and take over resources across team boundaries...
Security researchers discovered multi-tenant isolation failures in the Dify AI platform that allowed attackers to read private conversations from other...
A critical improper access control vulnerability (CVSS 9.6) in Red Hat's migration-planner allows an authenticated attacker to bypass ownership checks and...
A critical insecure direct object reference vulnerability allows authenticated users to pivot to any other user's profile by modifying an id parameter in...
A high-severity Insecure Direct Object Reference vulnerability in the WCFM Frontend Manager for WooCommerce plugin (up to v6.7.25) lets authenticated...