Description
The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL parameters.
No analysis available yet.
Remediation
Vendor Solution
Contact tech support from AIFU Information Technology Co.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-29311 | The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL parameters. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5296-cbf80-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T19:51:09.107Z
Reserved: 2021-10-12T00:00:00.000Z
Link: CVE-2021-42337
No data.
Status : Modified
Published: 2021-11-16T02:15:06.787
Modified: 2024-11-21T06:27:38.103
Link: CVE-2021-42337
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD