CVE 5.3 MEDIUM

Askbot 0.12.2 – Insecure Direct Object Reference (IDOR)_CVE-2026-1213

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Description

All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12.2.

Basic Information

ID CVE-2026-1213
Source Fluid Attacks
Published Jan 27, 2026 at 14:04

Affected Product

Vendor askbot
Product askbot
Version 0.12.2
Affected Versions askbot askbot 0.12.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.