- 
                Notifications
    You must be signed in to change notification settings 
- Fork 105
Closed
Description
With the new update, VRT considers all read-only IDORs P3.
But that's a really broad category of issues. It might be a same-tenant IDOR with semi-sensitive info, in which case P3 is a good fit.
It might also be a cross-tenant IDOR with access to highly sensitive info. Assuming open registration, that's CVSS High CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, so imho P3 is too low.
You could add a differentiation regarding same or cross tenant (P3 vs P2 or even P1), but that's still painting with a large brush. This might be a case for Varies, where the impact really depends on the data that is leaked.
Metadata
Metadata
Assignees
Labels
No labels