Description
Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection.This issue affects Envanty: before 1.0.6. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. The vulnerability was learned to be remediated through reporter information and testing.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version before 1.0.6
Credits
Şamil ALPAY
References
www.usom.gov.tr/bildirim/tr-26-0076