VYPR
Medium severity6.5NVD Advisory· Published Oct 10, 2026

CVE-2026-108164

CVE-2026-108164

Description

Open Source Social Network (OSSN) through 10.1 contains an insecure direct object reference vulnerability in components/OssnMessages/ossn_com.php that allows authenticated users to read other users' private message attachments. Attackers can request the /messages/attachment/{guid} route with sequential or guessed file GUIDs to retrieve attachments from private conversations without sender or recipient verification.

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.