Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter.
References
Link | Resource |
---|---|
https://www.exploit-db.com/exploits/50050 | Exploit Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-07-01 07:15
Updated : 2022-05-03 09:04
NVD link : CVE-2021-35337
Mitre link : CVE-2021-35337
JSON object : View
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
Products Affected
phone_shop_sales_management_system_project
- phone_shop_sales_management_system