THREAT OPS › Threat News › [GHSA] GHSA-2364-jh4q-m9vm (medium) — Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
[GHSA] GHSA-2364-jh4q-m9vm (medium) — Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
GHSA-2364-jh4q-m9vm Severity: medium CVE: None
Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
### Summary An Insecure Direct Object Reference (IDOR) vulnerability exists at the **GET /api/v1/organization/customer-default-source** endpoint. This flaw allows an authenticated attacker to bypass authorization checks and retrieve sensitive payment
MITRE ATT&CK techniques
- Email AddressesT1589.002
Indicators of compromise
- truongnguyen210044@gmail.comemail
- cloud.flowiseai.comdomain
Original source: https://github.com/advisories/GHSA-2364-jh4q-m9vm