Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
http://hshnudr.com | url repurposed not applicable |
https://www.sourcecodester.com/hashenudara/simple-doctors-appointment-project.html | product |
https://github.com/aznull/CVEs | third party advisory |