Executive brief
DijiDemi, an educational and publishing platform, contains a security flaw that allows users to bypass authorization controls. By manipulating specific identifiers in their requests, an authenticated user could potentially access information belonging to other users. This could lead to unauthorized data exposure and a breach of privacy for students or staff using the platform.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639 (Authorization Bypass Through User-Controlled Key), exists in the DijiDemi platform. The flaw resides in how the application handles user-supplied identifiers to retrieve records. A remote attacker with low-level authenticated access can manipulate these keys or identifiers in network requests to bypass authorization checks. This allows the attacker to view sensitive information that should be restricted to other users. The vulnerability is confirmed to affect versions through November 28, 2025.
Affected products
- Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi through 2025-11-28
Timeline
- 2025-12-10: disclosed
- 2025-12-10: advisory