This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter dfclientid through API request URLs which could lead to unauthorized access to sensitive information belonging to other users.
References
Link | Resource |
---|---|
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-10-04 13:15
Updated : 2024-10-16 15:44
NVD link : CVE-2024-47657
Mitre link : CVE-2024-47657
CVE.ORG link : CVE-2024-47657
JSON object : View
Products Affected
shilpisoft
- net_back_office
CWE
CWE-639
Authorization Bypass Through User-Controlled Key