Sceawere

Vulnerability Detail

CVE-2026-108164UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OSSN Insecure Direct Object Reference

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
opensource-socialnetwork
Product
opensource-socialnetwork
Attack Type
Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Open Source Social Network (OSSN) through 10.1 contains an insecure direct object reference vulnerability in components/OssnMessages/ossn_com.php that allows authenticated users to read other users' private message attachments. Attackers can request the /messages/attachment/{guid} route with sequential or guessed file GUIDs to retrieve attachments from private conversations without sender or recipient verification.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-10T14:16:37.663Z",
  "pubdate": "2026-10-10T14:16:37.663Z",
  "executiveSummary": "Open Source Social Network (OSSN) through version 10.1 contains an Insecure Direct Object Reference (IDOR) vulnerability within its messaging component. This flaw allows an authenticated user to access and download private message attachments belonging to other users. By manipulating the GUID (Globally Unique Identifier) parameter associated with attachment requests, an attacker can bypass authorization checks that should restrict access to content strictly within a user's private conversations. The vulnerability stems from a lack of server-side validation regarding the requester's permissions relative to the requested file resource. Successful exploitation requires an active user session but does not necessitate elevated administrative privileges, posing a significant risk to the confidentiality of private communications. This issue exposes sensitive user data, including personal files and private media, to unauthorized disclosure across the entire platform instance.",
  "technicalDetails": "The vulnerability is located in the file components/OssnMessages/ossn_com.php. The root cause is a failure to perform server-side access control checks before serving files requested via the /messages/attachment/{guid} route. Specifically, the application logic fails to verify if the currently authenticated user is either the sender or the intended recipient of the private message associated with the requested GUID.\nThe exploitation method relies on the predictability and incrementality of file GUIDs. An authenticated attacker can identify the endpoint responsible for retrieving message attachments. By iterating through sequential GUID values or attempting to guess valid identifiers, the attacker can force the server to respond with the binary data of files stored in the messages subsystem.\nThe attack flow follows these steps: 1) The attacker authenticates as a standard user within the OSSN instance. 2) The attacker identifies the URI structure /messages/attachment/{guid} used for retrieving file attachments. 3) The attacker constructs HTTP GET requests to this endpoint, systematically cycling through GUID values. 4) The application processes the request, locates the file associated with the provided GUID in the backend storage, and returns the file contents to the attacker without validating if the requester has legitimate access to the underlying message object.\nThis vulnerability is classified as an IDOR because the application relies on user-supplied input to reference internal objects without mediating that reference through an authorization layer. The absence of an 'ownership check' on the component-level database query allows for unauthorized data access. The vulnerability is present in all versions up to and including 10.1. Because the /messages/attachment/ endpoint does not verify session context against the file's message association, an attacker with basic user access can extract arbitrary private attachments from the entire database, potentially leading to widespread information disclosure and privacy breaches."
}
CVE-2026-108164: OSSN Insecure Direct Object Reference (MEDIUM Severity, CVSS: 6.5) | Sceawere