CVE-2024-12048 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authoriz…
High CVSS: 8.8

CVE-2024-12048

An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple API endpoints, allowing attackers to view, edit, and delete other users' information without proper authorization. Affected endpoints include but are not limited to /get/project/{project_id}, /get/schedule_data/{agent_id}, /delete/{agent_id}, /get/organisation/{organisation_id}, and /get/user/{user_id}.
Vendor
Superagi
Product
Superagi
CWE
CWE-304
Yayın Tarihi
2025-03-20 10:15:26
Güncelleme
2025-07-18 19:58:36
Source Identifier
security@huntr.dev
KEV Date Added
-

Kategoriler

Referanslar