GHSA-7jxv-2xpm-95jx
GitHub Security Advisory
⚠ Unreviewed
HIGH
Has CVE
Advisory Details
ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers with general user's privilege can remotely bypass authorization and access the hidden resources in the system and execute privileged functionalities.
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 29, 2025 6:37 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.