Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NGnu Savane
APPGnu< 3.13
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
IDOR
CWE
Related vulnerabilities
CVE-2024-29399HIGH7.6same product
An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code an...
CVE-2024-27632HIGH8.8same product
An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in th...
CVE-2024-27631MEDIUM6.0same product
Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate ...
CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same vendor
GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER
CVE-2014-7169CRITICAL9.8⚠ KEVPL ✓same vendor
GNU Bash — niekompletna łatka Shellshock umożliwia command injection (CVE-2014-7169)