CVE-2026-62945

⚪ Do wiadomości

Brak weryfikacji identyfikatorów w TREK pozwala na ujawnienie tytułów rezerwacji z prywatnych wyjazdów.

CVSS
4.3
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using findForeignLinkTarget() to verify that the referenced object belongs to the file's trip. An authenticated user with file-edit permission on any accessible trip can submit a foreign reservation identifier through POST /api/trips/:tripId/files/:id/link, POST /api/trips/:tripId/files, or PUT /api/trips/:tripId/files/:id. Subsequent reads through FILE_SELECT or getFileLinks() join the foreign reservation and return reservation_title, disclosing reservation existence and titles across private trip boundaries. This issue is fixed in version 3.1.3.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS4.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-08-20 22:17:46 UTC
Ostatnia modyfikacja (NVD)2026-09-18 20:09:01 UTC
Referencje