PT-2021-20892 · Sourcecodester · Sourcecodester Phone Shop Sales Managements System
Published
2021-07-01
·
Updated
2022-05-03
·
CVE-2021-35337
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Sourcecodester Phone Shop Sales Management System version 1.0
Description:
The issue allows an attacker to view invoices of different users by modifying the
id parameter, indicating a lack of proper access control. This could potentially expose sensitive information.Recommendations:
For Sourcecodester Phone Shop Sales Management System version 1.0, restrict access to the invoice viewing functionality to prevent unauthorized users from modifying the
id parameter and accessing other users' invoices. Consider implementing proper authentication and authorization mechanisms to ensure that only authorized users can view invoices.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Phone Shop Sales Managements System