CVE Published: 04/10/2024 |
CVE Updated: 04/10/2024 |
CVE Year: 2024 Source: CERT-In |
Vendor: Shilpi Computers |
Product: Net Back Office Status : PUBLISHED
CVE-2024-47657 Description
This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter dfclientid through API request URLs which could lead to unauthorized access to sensitive information belonging to other users.