Vulnerability Description
Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phone Shop Sales Management System Project | Phone Shop Sales Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/50050ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/50050ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2021-35337?
CVE-2021-35337 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id par...
How severe is CVE-2021-35337?
CVE-2021-35337 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-35337?
Check the references section above for vendor advisories and patch information. Affected products include: Phone Shop Sales Management System Project Phone Shop Sales Management System.