Insertion of Sensitive Information Into Sent Data
CVE-2024-50633
Summary
A Broken Object Level Authorization (BOLA) vulnerability in Indico versions through 3.3.2 allows attackers to access sensitive information via sending a crafted POST request to the component '/api/principals'.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-201 - Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
References
Advisory Timeline
- Published