Description
Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify the parameter of a specific query function to access other users' EC order details.
Problem types
CWE-639 Authorization bypass through User-Controlled key
Product status
Any version
References
www.twcert.org.tw/tw/cp-132-10938-97ddd-1.html
www.twcert.org.tw/en/cp-139-10940-d90bd-2.html