LubeLogger: IDOR in DuplicateRecordsToOtherVehicles Allows Copying Records from Any User's Vehicle Without Ownership Check
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.1epss 0.4%
probabilidad de explotación
0.4%top 70% de las CVE
explotación observada
noninguna fuente lo reporta
LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an authenticated user could submit caller-controlled recordIds to the DuplicateRecordsToOtherVehicles endpoint while naming destination vehicleIds the user could edit. The endpoint authorized the destination vehicles but fetched source records in Controllers/VehicleController.cs without checking UserCanEditVehicle for each existingRecord.VehicleId. This missing source-vehicle authorization allowed service, collision, upgrade, fuel, tax, supply, note, odometer, reminder, plan, inspection, and equipment records belonging to another user to be copied into an attacker-controlled vehicle, exposing record contents and attachment paths and creating persistent copies. This issue is fixed in version 1.6.8.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Productos afectados
hargata · lubelogReferencias
https://github.com/hargata/lubelog/commit/c8d5888ebc69e6a163e33f36200233ec845e5c57https://github.com/hargata/lubelog/issues/1398https://github.com/hargata/lubelog/pull/1395https://github.com/hargata/lubelog/releases/tag/v1.6.8https://github.com/hargata/lubelog/security/advisories/GHSA-3r34-mx83-q67r