CyberRota Analysis
AI-GeneratedVSee Clinic 7.1.26 and API 1.3.0 are vulnerable to an Insecure Direct Object Reference (IDOR) flaw in the /v1.3.0/api/files endpoint, allowing authenticated attackers to exploit the 'remark' request parameter. This vulnerability enables them to enumerate, access, and delete files belonging to other users, posing a significant risk to user data integrity and confidentiality. Organizations using these versions should prioritize remediation to protect sensitive information from unauthorized access and manipulation.
Original NVD Description
VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other users on the application server.
Related CVEs
Other vulnerabilities affecting the same vendor(s)