CVE-2021-42331
15.10.2021, 12:15
The Study Edit function of ShinHer StudyOnline System does not perform permission control. After logging in with users privilege, remote attackers can access and edit other users tutorial schedule by crafting URL parameters.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration
- CWE-285 - Improper AuthorizationThe software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
- CWE-862 - Missing AuthorizationThe software does not perform an authorization check when an actor attempts to access a resource or perform an action.