Impact
Service Center developed by BankPro E-Service Technology contains an Insecure Direct Object Reference that lets any authenticated remote user alter the parameters of a specific query function to retrieve another user’s electronic order details. This grants access to confidential personal and financial data, potentially enabling fraud or privacy violations. The weakness is a classic IDOR, classified as CWE‑639, and allows for information disclosure rather than code execution or denial of service.
Affected Systems
The vulnerability impacts the Service Center module of BankPro E-Service Technology. No specific product version numbers are provided; therefore every installation of this module that remains unpatched is susceptible. The vendor has acknowledged the flaw and implemented a server‑side patch.
Risk and Exploitability
With a CVSS score of 7.1 the flaw is of moderate to high severity, though the EPSS score is not available and the issue is not listed in CISA’s KEV catalog, suggesting limited public exploitation. Attackers would need to be authenticated and able to craft web requests to the vulnerable endpoint, making the attack vector remote and client‑side. The server‑side patch removes the risk, so the vulnerability is effectively mitigated and no further action is necessary for users who are on the patched system.
OpenCVE Enrichment