GHSA-93xg-c6hj-rp82HighCVSS 7.5
A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated...
🔗 CVE IDs covered (1)
📋 Description
A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.