An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://github.com/gugoan/economizzer | product |
https://www.economizzer.org | product |
https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-38872 | third party advisory exploit |