CVE-2026-108164: Open Source Social Network (OSSN) through 10.1 IDOR via Message Attachment Route
Open Source Social Network (OSSN) through 10.1 contains an insecure direct object reference vulnerability in components/OssnMessages/ossncom.php that allows authenticated users to read other users' private message attachments. Attackers can request the /messages/attachment/{guid} route with sequential or guessed file GUIDs to retrieve attachments from private conversations without sender or recipient verification.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated OSSN user can exploit it. The attacker does not need to be a participant in the private conversation containing the attachment.
What does an attacker need to retrieve private attachments?
The attacker needs a valid login and a message attachment GUID. GUIDs may be guessed or enumerated sequentially through the /messages/attachment/{guid} route.
What data is exposed?
Private message attachments may be disclosed. The affected route does not verify that the requester is the attachment sender or recipient.
Are installations running OSSN 10.1 affected?
Yes. The issue affects OSSN through version 10.1.