CVE-2023-42334: FL3XX Crew

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalate privileges via the user parameter.

Affected products

  • FL3XX Crew: version 2.10.37 only
  • FL3XX Dispatch: version 2.10.37 only

Published 2023-09-20. Last modified 2026-06-17.