A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as critical. This vulnerability affects unknown code of the component Listing Handler. The manipulation leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 1.0.2 is able to address this issue. It is recommended to upgrade the affected component.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://vuldb.com/?id.310270 | third party advisory vdb entry |
https://vuldb.com/?ctiid.310270 | signature vdb entry permissions required |
https://github.com/Stolichnayer/Summer-Pearl-Group-IDOR-XSS | related not applicable |
https://summerpearlgroup.gr/spgpm/releases | patch release notes |
https://www.youtube.com/watch?v=0wwuatTa6sU | media coverage exploit |