An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/fbkcs/CVE-2024-25270 |
![]() ![]() |
History
Fri, 13 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mirapolis
Mirapolis lms |
|
Weaknesses | CWE-639 | |
CPEs | cpe:2.3:a:mirapolis:lms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Mirapolis
Mirapolis lms |
|
Metrics |
cvssV3_1
|
Thu, 12 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Sep 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-25T16:10:42.384Z
Reserved: 2024-02-07T00:00:00.000Z
Link: CVE-2024-25270

Updated: 2024-09-12T20:00:26.540Z

Status : Modified
Published: 2024-09-12T19:15:03.290
Modified: 2025-03-25T17:15:50.983
Link: CVE-2024-25270

No data.