The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/76e8591f-120c-4cd7-b9a2-79f8d4d98aa8/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-06-05 06:15
Updated : 2024-06-11 17:14
NVD link : CVE-2024-4886
Mitre link : CVE-2024-4886
CVE.ORG link : CVE-2024-4886
JSON object : View
Products Affected
buddyboss
- buddyboss_platform
CWE
CWE-639
Authorization Bypass Through User-Controlled Key