Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter.
References
Link Resource
https://www.exploit-db.com/exploits/50050 Exploit Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-07-01T13:15:26

Updated: 2021-07-01T13:15:26

Reserved: 2021-06-23T00:00:00


Link: CVE-2021-35337

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-07-01T14:15:07.917

Modified: 2022-05-03T16:04:40.443


Link: CVE-2021-35337

JSON object: View

cve-icon Redhat Information

No data.

CWE