4.3
CVE-2026-62945
- EPSS -
- Veröffentlicht 20.08.2026 21:51:19
- Zuletzt bearbeitet 21.08.2026 16:17:52
- CVE-Watchlists
- Unerledigt
TREK: Cross-trip reservation title disclosure via file links
TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using findForeignLinkTarget() to verify that the referenced object belongs to the file's trip. An authenticated user with file-edit permission on any accessible trip can submit a foreign reservation identifier through POST /api/trips/:tripId/files/:id/link, POST /api/trips/:tripId/files, or PUT /api/trips/:tripId/files/:id. Subsequent reads through FILE_SELECT or getFileLinks() join the foreign reservation and return reservation_title, disclosing reservation existence and titles across private trip boundaries. This issue is fixed in version 3.1.3.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellermauriceboe
≫
Produkt
TREK
Version
< 3.1.3
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://github.com/liketrek/TREK/security/advisories/GHSA-r4cp-666p-8f69
https://github.com/liketrek/TREK/pull/1324
https://github.com/liketrek/TREK/commit/03cdb4d27689922460ba87085d04b426d4d40d26
https://github.com/liketrek/TREK/releases/tag/v3.1.3