The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL parameters.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.twcert.org.tw/tw/cp-132-5296-cbf80-1.html |
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2021-11-16T01:40:13.622076Z
Updated: 2024-09-16T19:51:09.107Z
Reserved: 2021-10-12T00:00:00
Link: CVE-2021-42337
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-11-16T02:15:06.787
Modified: 2024-11-21T06:27:38.103
Link: CVE-2021-42337
Redhat
No data.