Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter.
References
Link | Resource |
---|---|
https://www.exploit-db.com/exploits/50050 | Exploit Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-07-01T13:15:26
Updated: 2021-07-01T13:15:26
Reserved: 2021-06-23T00:00:00
Link: CVE-2021-35337
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-07-01T14:15:07.917
Modified: 2022-05-03T16:04:40.443
Link: CVE-2021-35337
JSON object: View
Redhat Information
No data.
CWE