PT-2021-20892 · Sourcecodester · Sourcecodester Phone Shop Sales Managements System

Published

2021-07-01

·

Updated

2022-05-03

·

CVE-2021-35337

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Sourcecodester Phone Shop Sales Management System version 1.0
Description: The issue allows an attacker to view invoices of different users by modifying the id parameter, indicating a lack of proper access control. This could potentially expose sensitive information.
Recommendations: For Sourcecodester Phone Shop Sales Management System version 1.0, restrict access to the invoice viewing functionality to prevent unauthorized users from modifying the id parameter and accessing other users' invoices. Consider implementing proper authentication and authorization mechanisms to ensure that only authorized users can view invoices.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-35337

Affected Products

Sourcecodester Phone Shop Sales Managements System