OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application.
References
Configurations
No configuration.
History
11 Mar 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-11 01:15
Updated : 2025-03-11 01:15
NVD link : CVE-2025-26656
Mitre link : CVE-2025-26656
CVE.ORG link : CVE-2025-26656
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization