Vulnerabilities (CVE)

Filtered by vendor Larvata Subscribe
Filtered by product Flygo
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-37214 1 Larvata 1 Flygo 2022-04-25 6.5 MEDIUM 8.8 HIGH
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command.