A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index of the file \handler\Account.go. The manipulation of the argument user_cookie leads to improper authorization. The exploit has been disclosed to the public and may be used.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://vuldb.com/?id.300569 | vdb entry permissions required technical description |
https://vuldb.com/?ctiid.300569 | signature vdb entry permissions required |
https://vuldb.com/?submit.517343 | third party advisory vdb entry |
https://github.com/38279/1/issues/1 | issue tracking exploit |
https://code-projects.org/ | product |