← Back to CVE List

CVE-2024-12048

Published: 2025-03-20T10:15Z
Last Modified: 2025-03-20T13:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple API endpoints, allowing attackers to view, edit, and delete other users' information without proper authorization. Affected endpoints include but are not limited to /get/project/{project_id}, /get/schedule_data/{agent_id}, /delete/{agent_id}, /get/organisation/{organisation_id}, and /get/user/{user_id}. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt