CVE-2024-55471
C# vulnerability analysis and mitigation

Overview

Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This vulnerability, identified as CVE-2024-55471 and disclosed on December 20, 2024, allows unauthorized users to access sensitive information of other users by manipulating the id parameter. The vulnerability affects the Oqtane Framework version 6.0.0 and earlier releases (NVD, Medium Blog).

Technical details

The vulnerability exists in the Oqtane.Controllers.UserController.Get endpoint accessible via http://localhost:5000/api/User/{id}?siteid=1. The endpoint lacks proper authorization checks to verify whether the requesting user has permission to access data for a specific id. The CVSS v3.1 base score is 6.5 (MEDIUM) with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N (NVD).

Impact

The vulnerability can lead to unauthorized data access, privacy breaches, and compromised application integrity. Attackers can view sensitive user information by manipulating the id parameter in API requests. This vulnerability could potentially serve as a stepping stone for more sophisticated attacks such as privilege escalation or account takeover (Medium Blog).

Mitigation and workarounds

The vulnerability has been patched by implementing proper authorization checks to ensure that user settings are only accessible to individual users or administrators. Organizations using affected versions should update to the latest version immediately. Additional recommended security measures include implementing robust authorization checks, using indirect references instead of direct object references, following secure API development practices, and conducting regular security testing (GitHub PR, Medium Blog).

Additional resources


SourceThis report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-64095CRITICAL9.8
  • C#C#
  • DNN.PLATFORM
NoYesOct 28, 2025
CVE-2025-62594MEDIUM5.5
  • C#C#
  • Magick.NET-Q8-OpenMP-x64
NoYesOct 27, 2025
CVE-2025-64094MEDIUM5.4
  • C#C#
  • DotNetNuke.Core
NoYesOct 28, 2025
CVE-2025-65955MEDIUM4.9
  • C#C#
  • ImageMagick-perl
NoYesDec 02, 2025
CVE-2025-62802MEDIUM4.3
  • C#C#
  • Dnn.Platform
NoYesOct 28, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management