PT-2026-90979 · Jaygajera17 · E-Commerce-Project-Springboot
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
jaygajera17 E-commerce-project-springBoot versions up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2
Description
An authorization bypass can be triggered remotely by manipulating the
userid argument within the updateUser() function of the UserController.java file.Recommendations
As a temporary workaround, restrict access to the
updateUser() function until the pending pull request is accepted and merged.Exploit
Fix
IDOR
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
E-Commerce-Project-Springboot