Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-107856

MEDIUM · 4.5 CVSS Gepubliceerd: CWE-639

Beschrijving NL

CiviForm vereenvoudigt aanvragen voor uitkeringsprogramma's van de overheid door sollicitatiegegevens te hergebruiken voor meerdere uitkeringsprogramma's. Voorafgaand aan 3.33.0 controleert GET /admin/tiDash/editClientForm/:accountId of de aanvrager een vertrouwde tussenpersoon is, maar showEditClientForm voert een ruwe lookupAccount (accountId) uit zonder te bevestigen dat het burgeraccount tot de vertrouwde intermediaire groep van de aanvrager behoort. Een geverifieerde vertrouwde tussenpersoon kan accountId-waarden opsommen en de weergavenaam van de aanvrager lezen, inclusief de naam en het e-mailadres van de burger, voor accounts buiten de groep van de tussenpersoon. Dit probleem is opgelost in versie 3.33.0.

Origineel (Engels) tonen

CiviForm simplifies applications for government benefits programs by reusing applicant data across multiple benefit applications. Prior to 3.33.0, GET /admin/tiDash/editClientForm/:accountId verifies that the requester is a Trusted Intermediary but showEditClientForm performs a raw lookupAccount(accountId) without confirming that the citizen account belongs to the requester's trustedIntermediaryGroup. An authenticated Trusted Intermediary can enumerate accountId values and read the applicant display name, including the citizen's name and email address, for accounts outside the intermediary's group. This issue is fixed in version 3.33.0.

References