What the vulnerability does
01Description
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
Explanation of Vulnerability in Simple Terms
Do Lasso versions 358 and earlier contain an authorization bypass vulnerability in how user-controlled keys are validated. An attacker can modify request parameters to bypass access controls and alter data or disrupt service without authentication. The vulnerability affects integrity and availability but not confidentiality.
What an attacker can do
Modify or delete data and disrupt service availability without logging in.
Potential impact on your site
Unauthorized users can alter or delete content and cause service disruptions without credentials.
Conditions required to exploit
Network access to the Do Lasso application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities