CVE-2022-30760
Last modified
CVE-2022-30760 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint.. EPSS estimates a 0.88% chance of exploitation in the next 30 days.
Description
An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ihb-Eg | Fn2web | < 2.04.09.016 |
References
- https://homepage.ruhr-uni-bochum.de/Christian.Krug-q97/CVE-2022-30760.htmlExploit, Third Party Advisory
- https://wiki.ihb-eg.de/doku.php/releasenotes/fn2web2.04.09Release Notes, Vendor Advisory
- https://homepage.ruhr-uni-bochum.de/Christian.Krug-q97/CVE-2022-30760.htmlExploit, Third Party Advisory
- https://wiki.ihb-eg.de/doku.php/releasenotes/fn2web2.04.09Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-30760?
How severe is CVE-2022-30760?
How do I fix CVE-2022-30760?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-30755Improper authentication vulnerability in AppLock prior to SM…7.8
- CVE-2022-30756Implicit Intent hijacking vulnerability in Finder prior to S…7.8
- CVE-2022-30757Improper authorization in isemtelephony prior to SMR Jul-202…3.3
- CVE-2022-30758Implicit Intent hijacking vulnerability in Finder prior to S…5.5
- CVE-2022-30759In Nokia One-NDS (aka Network Directory Server) through 20.9…8.8
- CVE-2022-3076The CM Download Manager WordPress plugin before 2.8.6 allows…7.2
- CVE-2022-30763Janet before 1.22.0 mishandles arrays.7.5
- CVE-2022-30765Calibre-Web before 0.6.18 allows user table SQL Injection.9.8
- CVE-2022-30767nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 …9.8
- CVE-2022-30768A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36…5.4
- CVE-2022-30769Session fixation exists in ZoneMinder through 1.36.12 as an …4.6
- CVE-2022-3077A buffer overflow vulnerability was found in the Linux kerne…5.5
Are you affected by CVE-2022-30760?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
