This vulnerability exists in the Shilpi Net Back Office...
High severity
Unreviewed
Published
Oct 4, 2024
to the GitHub Advisory Database
•
Updated Oct 16, 2024
Description
Published by the National Vulnerability Database
Oct 4, 2024
Published to the GitHub Advisory Database
Oct 4, 2024
Last updated
Oct 16, 2024
This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter dfclientid through API request URLs which could lead to unauthorized access to sensitive information belonging to other users.
References