IDOR in Messages function in admidio/admidio
Valid
Reported on
Jun 9th 2022
Description
An user can view other users' private messages, join the conversation, delete messages if they know messages uuid
Proof of Concept
1. A send B a priavte messages/email
2. C can view messages, join the conversation, delete messages if C know messages uuid
Impact
This vulnerability is capable of leak private information, delete chats
We are processing your report and will contact the
admidio
team within 24 hours.
10 months ago
We have contacted a member of the
admidio
team and are waiting to hear back
9 months ago
We have sent a
follow up to the
admidio
team.
We will try again in 7 days.
9 months ago
The researcher's credibility has increased: +7
Thanks for researching this issue. I'm working on a fix and will release a new version soon.
The researcher's credibility has slightly increased as a result of the maintainer's thanks: +1
to join this conversation