Vieni a trovarci
Via Pret, 1 - Brunello (VA) - a pochi KM da Milano
Social Media
Contattaci
0332.802.111

Post di Andrea Ferrario

CVE-2026-51367: Insecure Direct Object Reference (IDOR) Leading to Unauthorized Data Access
lug 30

CVE-2026-51367: Insecure Direct Object Reference (IDOR) Leading to Unauthorized Data Access

Summary

Field

Value

CVE ID

CVE-2026-51367

Product

Vedo Suite (Bottinelli Informatica)

Affected Version(s)

v1.2.5

Vulnerability Class

CWE-639: Authorization Bypass Through User-Controlled Key

Attack Vector

Network (HTTP API)

Privileges Required

Low (authenticated application user)

User Interaction

None

Impact

Confidentiality breach / unauthorized access to other users’ data

Estimated CVSS 3.1

8.7 (High) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Leggi di più

CVE-2026-51366: SQL Injection Leading to Remote Code Execution
lug 30

CVE-2026-51366: SQL Injection Leading to Remote Code Execution

Summary

Field

Value

CVE ID

CVE-2026-51366

Product

Vedo Suite (Bottinelli Informatica)

Affected Version(s)

v1.2.5 (and possibly earlier/other versions using the same endpoint logic — unconfirmed)

Vulnerability Class

CWE-89: SQL Injection

Secondary Impact

CWE-78: OS Command Injection (via xp_cmdshell)

Attack Vector

Network (HTTP GET)

Privileges Required

Low (authenticated application user)

User Interaction

None

Backend

Microsoft SQL Server

Estimated CVSS 3.1

9.9 (Critical) — AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Leggi di più

Vulnerabilità scoperta dal Red Team di CybergON: come funziona e cosa fare
gen 07

Vulnerabilità scoperta dal Red Team di CybergON: come funziona e cosa fare

Il Red Team di CybergON ha recentemente scoperto la CVE-2024-44349. La CVE è stata identificata durante l’attività di penetration testing sulla web application di un cliente, nello specifico un Warehouse Management System (WMS). Lo strumento coinvolto è stato sviluppato da Anteeo, una software house polacca. La vulnerabilità si realizza tramite SQL Injection (SQLi), che consente attraverso comandi costruiti su misura di interferire o interrogare diversamente i dati presenti nel database sottostante una specifica web application.

BANNER BLOG (1)
Leggi di più

    Ultimi post pubblicati