VYPR
Unrated severityNVD Advisory· Published Nov 9, 2024· Updated Oct 14, 2025

data.all authenticated users can perform mutating update operations on persisted notification records

CVE-2024-10953

Description

An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.all for group notifications that their user is not a member of.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.