teklifolustur_app is a web-based PHP application that allows users to create, manage, and track quotes for their clients. Prior to commit dd082a134a225b8dcd401b6224eead4fb183ea1c, an Insecure Direct Object Reference (IDOR) vulnerability exists in the offer view functionality. Authenticated users can manipulate the offer_id parameter to access offers belonging to other users. The issue is caused by missing authorization checks ensuring that the requested offer belonged to the currently authenticated user. Commit dd082a134a225b8dcd401b6224eead4fb183ea1c contains a patch.
Metrics
Affected Vendors & Products
References
History
Tue, 20 Jan 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sibercii6-crypto
Sibercii6-crypto teklifolustur App |
|
| Vendors & Products |
Sibercii6-crypto
Sibercii6-crypto teklifolustur App |
Mon, 19 Jan 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | teklifolustur_app is a web-based PHP application that allows users to create, manage, and track quotes for their clients. Prior to commit dd082a134a225b8dcd401b6224eead4fb183ea1c, an Insecure Direct Object Reference (IDOR) vulnerability exists in the offer view functionality. Authenticated users can manipulate the offer_id parameter to access offers belonging to other users. The issue is caused by missing authorization checks ensuring that the requested offer belonged to the currently authenticated user. Commit dd082a134a225b8dcd401b6224eead4fb183ea1c contains a patch. | |
| Title | teklifolustur_app's IDOR vulnerability allows unauthorized access to other users' offers | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-01-19T18:42:56.765Z
Updated: 2026-01-19T18:42:56.765Z
Reserved: 2026-01-16T15:46:40.842Z
Link: CVE-2026-23843
No data.
Status : Received
Published: 2026-01-19T19:16:04.660
Modified: 2026-01-19T19:16:04.660
Link: CVE-2026-23843
No data.