CVE-2024-47653
04.10.2024, 13:15
This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this vulnerability by placing or cancelling requests through API request body leading to unauthorized modification of requests belonging to the other users.Enginsight
Vendor | Product | Version |
---|---|---|
shilpisoft | client_dashboard | 𝑥 < 9.7.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration