VYPR
Medium severity4.3NVD Advisory· Published Jun 10, 2021· Updated Jun 17, 2026

CVE-2021-31927

CVE-2021-31927

Description

An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. It was fixed in v2021.1.0.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:annexcloud:loyalty_experience_platform:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:annexcloud:loyalty_experience_platform:*:*:*:*:*:*:*:*range: <2020.1.0.1
    • (no CPE)range: <2021.1.0.1, >=2021.1.0.2
  • Annex Cloud/Loyalty Experience Platformdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.