Executive brief
The Dinibh Patrol Tracking System, used for managing security personnel and patrol logs, contains a security flaw that allows users to bypass authorization. By manipulating specific identifiers, an authenticated user can access or modify data belonging to others. This could lead to unauthorized access to sensitive patrol records, tampering with security logs, or a complete compromise of the system's data integrity.
Technical details
The Dinibh Patrol Tracking System is vulnerable to an Authorization Bypass Through User-Controlled Key (CWE-639), also known as Insecure Direct Object Reference (IDOR). An attacker with low-level authenticated access can manipulate input keys or identifiers (such as IDs in a URL or API request) to access or modify records they are not authorized to view. This vulnerability exists in versions through 10022026. The attack is network-reachable and requires no user interaction, potentially allowing for full compromise of confidentiality, integrity, and availability. As of the disclosure date, the vendor has not responded to reports of this issue.
Affected products
- Dinibh Puzzle Software Solutions Patrol Tracking System through 10022026
Timeline
- 2026-02-10: disclosed
- 2026-02-10: advisory: Advisory published by USOM/TR-CERT