CVE-2024-7473 - Lunary-ai Lunary IDOR

3 weeks ago 9
ARTICLE AD BOX
CVE ID : CVE-2024-7473
Published : Oct. 29, 2024, 1:15 p.m. | 24 minutes ago
Description : An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' prompts by manipulating the 'id' parameter in the request. The issue is fixed in version 1.4.3.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article