CyberRota Analysis
AI-GeneratedA vulnerability in the foreUP customer REST API permits authenticated, low-privilege users to access endpoints that expose records belonging to other users, bypassing ownership verification. This could lead to unauthorized data exposure, impacting user privacy and potentially violating data protection regulations. Organizations utilizing this API should prioritize remediation to safeguard sensitive user information and maintain compliance.
Original NVD Description
A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of other users without checking that the caller owns the data associated with that record.