CVE-2024-7473 Information
Nov 01, 2024
cve
Description
An IDOR vulnerability exists in the ‘Evaluations’ function of the ‘umgws datasets’ section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users’ prompts by manipulating the ‘id’ parameter in the request. The issue is fixed in version 1.4.3.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Reference
https://huntr.com/bounties/afecd927-b5f6-44ba-9147-5c45091beda5 https://github.com/lunary-ai/lunary/commit/88b55b01fcbab0fbbc5b8032a38d0345af98ecfa
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
6.5
Share on: