CVE-2024-47657
04.10.2024, 13:15
This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter dfclientid through API request URLs which could lead to unauthorized access to sensitive information belonging to other users.Enginsight
Vendor | Product | Version |
---|---|---|
shilpisoft | net_back_office | 𝑥 < 5.5.002 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration