CVE-2024-4886: BuddyBoss Platform < 2.6.0 - Subscriber+ Comment on Private Post via IDOR
Published Jun 5, 2024
·Updated
The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request
Affected Software
1 affected component
Buddyboss Buddyboss Platform Wordpress<2.6.00
Event History
Jun 5, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Apr 1, 57258
Event
via FIRST·07:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-4886?
CVE-2024-4886 is categorized as a critical vulnerability due to its implications on unauthorized access to private posts.
2
How do I fix CVE-2024-4886?
To mitigate CVE-2024-4886, update Buddyboss Platform to version 2.6.00 or later.
3
Who is affected by CVE-2024-4886?
CVE-2024-4886 affects users of Buddyboss Platform versions prior to 2.6.00 on WordPress.
4
What type of vulnerability is CVE-2024-4886?
CVE-2024-4886 is an Insecure Direct Object Reference (IDOR) vulnerability that can be exploited by manipulating request IDs.
5
Can CVE-2024-4886 be exploited by regular users?
Yes, CVE-2024-4886 can be exploited by regular users who can manipulate the ID in their requests to comment on private posts.