A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the file /queryTotal of the component Product Statistics Handler. The manipulation of the argument isDelete with the input 1 leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://vuldb.com/?id.306604 | vdb entry third party advisory technical description |
https://vuldb.com/?ctiid.306604 | vdb entry permissions required signature |
https://vuldb.com/?submit.560778 | vdb entry third party advisory |
https://www.cnblogs.com/aibot/p/18830908 | third party advisory exploit |