PT-2021-21609 · Laravel · Laravel Booking System Booking Core
Published
2021-10-04
·
Updated
2022-07-12
·
CVE-2021-37331
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Laravel Booking System Booking Core version 2.0
Description
The issue allows unauthorized access to sensitive information. Specifically, on the Verifications page, after uploading an ID Card or Trade License and viewing it, an attacker can view ID Cards and Trade Licenses of other vendors or users by modifying the URL.
Recommendations
For Laravel Booking System Booking Core version 2.0, consider restricting access to the Verifications page and ensure proper validation of user input to prevent unauthorized access to sensitive information. As a temporary workaround, restrict the ability to view ID Cards and Trade Licenses of other vendors or users until a proper fix is implemented.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Laravel Booking System Booking Core