{"id":"CVE-2026-1213","aliases":["GHSA-r2jv-fwfr-4j8c","PYSEC-2026-1193"],"url":"https://o3.security/vulnerability/CVE-2026-1213","summary":"Askbot 0.12.2 - Insecure Direct Object Reference (IDOR)","details":"All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12.2.","published":"2026-01-27T14:04:18.274Z","modified":"2026-08-07T11:31:33.972781005Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"askbot","fixedVersion":"0.12.3"}],"fix":{"url":"https://github.com/ASKBOT/askbot-devel/commit/3da3d75f35204aa71633c7a315327ba39cb6295d","label":"ASKBOT/askbot-devel@3da3d75"},"references":[{"type":"WEB","url":"https://askbot.com/"},{"type":"WEB","url":"https://pypi.python.org"},{"type":"ADVISORY","url":"https://fluidattacks.com/advisories/ghost"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1213.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1213"},{"type":"FIX","url":"https://github.com/ASKBOT/askbot-devel/commit/3da3d75f35204aa71633c7a315327ba39cb6295d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:33.972781005Z"}}