An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data.
Link | Tags |
---|---|
https://github.com/onEpAth936/cve/blob/master/bug_e/edoc-doctor-appointment-system | third party advisory |
https://github.com/HashenUdara/edoc-doctor-appointment-system | third party advisory product |