← back
CVE-2026-1213

Askbot 0.12.2 - Insecure Direct Object Reference (IDOR)

CVSS 5.3 MEDIUMEPSS 0.3%CWE-639
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
27 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12.2.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
askbot · askbot

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →