Tag

#Improper Authorization

blogHIGH 7.1

Understanding and Defending Against Cross-Database IDOR in ArcadeDB

This educational analysis covers a critical vulnerability in ArcadeDB, a cross-database Insecure Direct Object Reference (IDOR) issue that allows unauthorized access to databases. We will delve into the root cause, attack surface, exploitation mechanics, real-world impact, detection strategies, and defensive measures.

1 source
articleMEDIUM 5.4

CVE-2026-14693: Improper Authorization in SourceCodester Multi-Vendor Online Grocery Management System 1.0

A vulnerability has been discovered in the SourceCodester Multi-Vendor Online Grocery Management System 1.0, specifically in the `cancel_order` function of the `classes/Master.php` file. This flaw leads to improper authorization, allowing remote attackers to manipulate the system without proper permissions. The vulnerability has a CVSS score of 5.4 and is classified as medium severity. While it has not been reported as actively exploited, a proof-of-concept exploit has been published.

1 source
blogHIGH 7.1

Understanding Improper Authorization in DevGuard: A Public Asset Security Risk

This blog post explains a security vulnerability in DevGuard, specifically an improper authorization issue affecting public assets. The vulnerability allows any authenticated user to create, update, and delete VEX rules and other vulnerability-triage write endpoints on public assets, impacting the integrity of the vulnerability picture.

1 source