Executive brief
Netiket ApplyLogic is an enterprise software solution that has been found to contain a security flaw in how it handles user permissions. An attacker with basic user access can manipulate specific identifiers to gain unauthorized access to data or perform actions they are not permitted to do. This could lead to the unauthorized modification of sensitive business information or disruption of operations.
Technical details
An authorization bypass vulnerability (CWE-639) exists in Netiket ApplyLogic through version 01.12.2025. The flaw stems from the application's failure to properly validate that a user-controlled key or identifier belongs to the authenticated user before performing requested actions. A remote attacker with low-level privileges can exploit this by modifying parameters (such as IDs in a URL or request body) to access or modify records belonging to other users or the system. This allows for the exploitation of trusted identifiers, potentially leading to high integrity impact and moderate confidentiality and availability impacts.
Affected products
- Netiket Information Technologies Ltd. Co. ApplyLogic through 01.12.2025
Timeline
- 2025-12-11: disclosed: Initial publication of the CVE record.