VulnerabilityModified
CVE-2023-0944
Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update arbitrary user session data such as username, email and password.
MEDIUM 4.3EPSS 0.48%
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update arbitrary user session data such as username, email and password. This is possible because the application is vulnerable to IDOR, it does not correctly validate user permissions with respect to certain actions that can be performed by the user.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- imaworldhealth/bhima
- Source
- help@fluidattacks.com
References
- https://fluidattacks.com/advisories/stewart/Exploit, Third Party Advisory
- https://github.com/IMA-WorldHealth/bhima/Product
- https://fluidattacks.com/advisories/stewart/Exploit, Third Party Advisory
- https://github.com/IMA-WorldHealth/bhima/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.