java_shop 1.0 is vulnerable to Incorrect Access Control,...
Moderate severity
Unreviewed
Published
Nov 15, 2024
to the GitHub Advisory Database
•
Updated Nov 22, 2024
Description
Published by the National Vulnerability Database
Nov 15, 2024
Published to the GitHub Advisory Database
Nov 15, 2024
Last updated
Nov 22, 2024
java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.
References