The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.
Solution:
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-8166-085c4-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-8167-a2c0d-2.html | third party advisory |