Smart Parking Management System from Honding Technology has a Missing Authorization vulnerability, allowing remote attackers with regular privileges to access a specific functionality to create administrator accounts, and subsequently log into the system using those accounts.
Solution:
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-10170-e2435-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-10171-44c0a-2.html | third party advisory |