Skip to content

Instantly share code, notes, and snippets.

@AliAlsinan
AliAlsinan / gist:0323e57d2345ef0b4e73c803dba93486
Created December 29, 2020 05:29
CORMS - Insecure direct object references (IDOR)
[description]
In Correspondence Management System (corms) in Newgen eGov 12.0, an
attacker can modify other users' profile information by manipulating
the unvalidated UserIndex parameter, aka Insecure Direct Object
Reference.
------------------------------------------
[VulnerabilityType Other]
Insecure direct object references (IDOR)
------------------------------------------
[Vendor of Product]