Executive brief
Chiline Cloud is a cloud-based application platform developed by Inventec Appliances. An unauthenticated attacker can read other users' sensitive data by modifying specific request parameters, potentially exposing customer information, business data, and confidential records stored in the system.
Technical details
Chiline Cloud contains an Insecure Direct Object Reference (IDOR) vulnerability in which predictable or enumerable object references are not properly protected with authorization controls. An unauthenticated remote attacker can modify a specific parameter in requests to access objects belonging to other users, resulting in unauthorized disclosure of sensitive data. The vulnerability requires no authentication, user interaction, or special attack complexity—attackers need only send crafted network requests. The vendor has deployed a security patch server-side, and users receive automatic protection without requiring action.
Affected products
- Inventec Appliances Chiline Cloud 4.5.9 and earlier
Timeline
- 2026-08-10: disclosed
- 2026-08-10: patched: Vendor completed deployment of security patch server-side