CyberRota Analysis
AI-GeneratedA vulnerability in the dmWidget component of the diem-project, affecting versions up to 5.1.3, allows for an authorization bypass through manipulation of the widget_id argument in the BasedmWidgetActions.class.php file. This issue can be exploited remotely, and a public exploit is available, making it critical for organizations using this software to prioritize applying the provided patch (116974edfb9a5b8bd69cb13586dc62bcdbb485ad) to mitigate potential risks. Users of the affected versions should take immediate action to secure their systems.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argument widget_id leads to authorization bypass. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is 116974edfb9a5b8bd69cb13586dc62bcdbb485ad. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.