CVE-2021-35337
PoC —CVSS 3.1
4.3 medium
EPSS
<1%p55
Published
()
Modified
Description
Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter.
- Vendors
- phone shop sales management system project
- Products
- phone shop sales management system
- Weakness
- CWE-639
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.