Executive brief
OMICARD EDM, an enterprise direct marketing and email management platform, contains a security flaw that allows unauthorized individuals to access user information. By manipulating specific web parameters, an attacker can retrieve the email addresses of registered users without needing to log in. This could lead to large-scale data harvesting, increasing the risk of targeted phishing attacks or privacy breaches for the organization's customers and staff.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in ITPison OMICARD EDM versions 5.8 through 6.0.5.8. The flaw is located in a component that handles user-specific data requests where authorization checks are insufficient. An unauthenticated remote attacker can exploit this by sending crafted HTTP requests with modified parameters (such as user IDs) to the server. Successful exploitation allows the attacker to bypass intended access controls and retrieve sensitive information, specifically user email addresses. Users are advised to contact the vendor for a patch.
Affected products
- ITPison (沛盛資訊) OMICARD EDM 5.8 to 6.0.5.8
Timeline
- 2026-06-02: advisory: Initial disclosure by TWCERT/CC
- 2026-06-04: disclosed: NVD publication date