Skip to content

Instantly share code, notes, and snippets.

[Suggested description]
An Insecure Direct Object Reference (IDOR) vulnerability in eyecomms eyeCMS through 2019-10-15
allows any candidate to change other candidates' personal
information (first name, last name, email, CV, phone number, and all
other personal information) by changing the value of the candidate id
(the id parameter).
[Vendor of Product]
eyecomms
[Suggested description]
A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any
candidate to take over another candidate's account (by also exploiting CVE-2019-17604) via
a modified candidate id and an additional password parameter,
The outcome is that the password of this other candidate is changed.
[Vendor of Product]
eyecomms
[Affected Product Code Base]