A critical Insecure Direct Object Reference (IDOR) vulnerability was recently discovered in ExHub, a cloud-based platform for hulia-based development.
This flaw allowed attackers to modify web hosting configurations of any project without proper authorization, posing significant risks to affected systems.
Misconfigurations may cause outages or make services unavailable. Furthermore, attackers may be able to escalate privileges or chain attacks for additional exploitation due to compromised configurations.
ExHub offers cloud hosting, project collaboration, and deployment features. Among its functionalities is the ability for users to configure web hosting settings for their projects. These configurations determine how projects are deployed and accessed.
Ideally, only authorized users should be able to modify these settings. However, due to improper implementation of access controls, unauthorized users could exploit the system by simply knowing a project’s unique identifier.
The vulnerability resided in ExHub’s API for project deployment configuration. Specifically, the API lacked robust authorization checks, enabling any user—regardless of their role or authentication status—to send crafted requests and alter hosting settings.
The researcher, Abhi Sharma who identified this issue was awarded a $1,500 bounty, along with a $200 bonus for the detailed report.
The exploitation process involved minimal technical complexity:
Craft a POST request
This vulnerability effectively allowed unauthorized users to perform administrative actions such as changing machine types, ports, and DNS configurations—actions that should have been restricted to high-privilege roles.
The consequences of this IDOR vulnerability were severe where attackers could manipulate deployment configurations, potentially gaining unauthorized access to sensitive resources.
Misconfigurations could lead to downtime or render services inaccessible. Further, exploited configurations might enable attackers to escalate privileges or chain attacks for further exploitation.
The vulnerability was rated as Critical (CVSS score 9.8) but later downgraded to High (8.8) due to assumptions about the difficulty of obtaining project IDs.
To address this vulnerability:
This incident underscores several critical lessons for developers and organizations:
By enforcing strict access controls and adopting secure-by-design principles, companies can safeguard their platforms from exploitation and build trust with their users.
PCI DSS 4.0 & Supply Chain Attack Prevention – Free Webinar
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…