Description
Authorization Bypass Through User-Controlled Key vulnerability in Sayful Islam Upcoming Events Lists allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Upcoming Events Lists: from n/a through 1.4.0.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version
Credits
Nabil Irawan (Patchstack Alliance)
References
patchstack.com/...ct-references-idor-vulnerability?_s_id=cve