CVE Published: 03/10/2023 |
CVE Updated: 19/09/2024 |
CVE Year: 2023 Source: INCIBE |
Vendor: Universitat Politècnica de València (UPV) |
Product: UPV PEIX Status : PUBLISHED
CVE-2023-2544 Description
Authorization bypass vulnerability in UPV PEIX, affecting the component "pdf_curri_new.php". Through a POST request, an authenticated user could change the ID parameter to retrieve all the stored information of other registered users.
Metrics
CVSS Version: 3.1 |
Base Score: 5.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N