{"id":"CVE-2026-1213","summary":"Askbot 0.12.2 - Insecure Direct Object Reference (IDOR)","details":"All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12.2.","aliases":["GHSA-r2jv-fwfr-4j8c","PYSEC-2026-1193"],"modified":"2026-08-12T03:51:27.696602088Z","published":"2026-01-27T14:04:18.274Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1213.json","unresolved_ranges":[{"extracted_events":[{"introduced":"0.12.2"},{"last_affected":"0.12.2"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"Fluid Attacks","cwe_ids":["CWE-639"]},"references":[{"type":"WEB","url":"https://askbot.com/"},{"type":"WEB","url":"https://pypi.python.org"},{"type":"ADVISORY","url":"https://fluidattacks.com/advisories/ghost"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1213.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1213"},{"type":"FIX","url":"https://github.com/ASKBOT/askbot-devel/commit/3da3d75f35204aa71633c7a315327ba39cb6295d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/askbot/askbot-devel","events":[{"introduced":"0"},{"fixed":"3da3d75f35204aa71633c7a315327ba39cb6295d"}],"database_specific":{"source":"REFERENCES"}}],"versions":["0.7.51","0.7.50","0.7.49","0.7.48","0.7.44","0.7.41","0.7.31","0.7.30","0.7.26","0.7.25"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1213.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}