ZeroHour

CVE-2023-36238

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p44
Published
()
Modified
Description

Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.

Vendors
webkul
Products
bagisto
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.