VYPR
Medium severity4.3NVD Advisory· Published Jun 9, 2022· Updated Jun 17, 2026

CVE-2022-30760

CVE-2022-30760

Description

An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • ihb eG/FlexNowdescription
  • ihb eG/FlexNowllm-fuzzy
    Range: <2.04.09.016

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.