IDOR in notification function in limesurvey/limesurvey
Valid
Reported on
Jun 26th 2023
Description
By manipulating the notId
, a user can view the notification of other users
Proof of Concept
Step 1: Login as user demo
, click on a notification and see that the notification has a notId
as 227
.
Step 2: Open another browser and login as
user
.
Step 3: Access the URL to view the notification of user
demo
https://demo.limesurvey.org/index.php?r=admin/notification&sa=getNotificationAsJSON¬Id=227
Impact
By manipulating the notID
, the attacker can view the notification of any user if he knows the notId
which is guessable
We are processing your report and will contact the
limesurvey
team within 24 hours.
3 months ago
We have contacted a member of the
limesurvey
team and are waiting to hear back
3 months ago
The researcher has received a minor penalty to their credibility for miscalculating the severity: -1
The researcher's credibility has increased: +7
The fix bounty has been dropped
This vulnerability will not receive a CVE
to join this conversation