Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21980 | Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.exploit-db.com/exploits/50050 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T00:33:51.342Z
Reserved: 2021-06-23T00:00:00
Link: CVE-2021-35337
No data.
Status : Modified
Published: 2021-07-01T14:15:07.917
Modified: 2024-11-21T06:12:14.427
Link: CVE-2021-35337
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD