CVE-2024-12048 Information

Description

An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple API endpoints allowing attackers to view edit and delete other users’ information without proper authorization. Affected endpoints include but are not limited to /get/project/project_id /get/schedule_data/agent_id /delete/agent_id /get/organisation/organisation_id and /get/user/user_id.

Reference

https://huntr.com/bounties/6def3e3a-c443-44bb-b20e-3e69b48f37dc https://huntr.com/bounties/6def3e3a-c443-44bb-b20e-3e69b48f37dc

Share on: