CVE-2024-7473

An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' prompts by manipulating the 'id' parameter in the request. The issue is fixed in version 1.4.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lunary:lunary:1.3.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-29 13:15

Updated : 2024-11-03 17:15


NVD link : CVE-2024-7473

Mitre link : CVE-2024-7473

CVE.ORG link : CVE-2024-7473


JSON object : View

Products Affected

lunary

  • lunary
CWE
CWE-639

Authorization Bypass Through User-Controlled Key