Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key
No sign of exploitation. No public exploitation artifact known so far.
Kiteworks Secure Data Forms has a flaw where logged-in users can modify form settings and approval workflows of other users' forms because the system doesn't properly verify who owns each form. This allows attackers to bypass intended access controls and interfere with other people's business processes.
An IDOR vulnerability exists in Kiteworks Secure Data Forms (pre-9.3.0) where authenticated users can tamper with approval flow configurations of forms belonging to other users due to insufficient authorization checks on resource ownership. The attack vector is network-based and requires prior authentication; impact includes unauthorized modification of form workflows and approval processes.