This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter dfclientid through API request URLs which could lead to unauthorized access to sensitive information belonging to other users.
This Cyber News was published on www.tenable.com. Publication date: Sat, 05 Oct 2024 09:11:03 +0000