A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulation of the argument ID leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://vuldb.com/?id.317088 | technical description vdb entry third party advisory |
https://vuldb.com/?ctiid.317088 | signature vdb entry permissions required |
https://vuldb.com/?submit.619276 | vdb entry third party advisory |
https://github.com/jishenghua/jshERP/issues/124 | exploit issue tracking |