Security Advisory

CVE-2022-30760

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-06-09 15:14:10
Last updated 2024-08-03 06:56:14
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint.