Home
HIGH: 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
8.0
affected
Description
Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to other customers through the 'id' parameter in '/admin/ticket_a4.php'.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
8.0
Credits
Ignacio Aldarabi
References
www.incibe.es/...multiple-vulnerabilities-sergestec-products