CVE-2024-12048 Information
Mar 21, 2025
cve
Description
An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple API endpoints allowing attackers to view edit and delete other users’ information without proper authorization. Affected endpoints include but are not limited to /get/project/project_id /get/schedule_data/agent_id /delete/agent_id /get/organisation/organisation_id and /get/user/user_id.
Reference
https://huntr.com/bounties/6def3e3a-c443-44bb-b20e-3e69b48f37dc https://huntr.com/bounties/6def3e3a-c443-44bb-b20e-3e69b48f37dc
Share on: