漏洞标题
RupeeWeb 交易平台存在授权不足漏洞
漏洞描述信息
该漏洞存在于RupeeWeb交易平台中,由于某些API端点在处理增加和删除操作时授权控制不足。成功利用此漏洞可能允许经过身份验证的远程攻击者修改属于其他用户账户的信息。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
漏洞类别
授权机制不正确
漏洞标题
Insufficient Authorization Vulnerability in RupeeWeb trading platform
漏洞描述信息
This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this vulnerability could allow an authenticated remote attacker to modify information belonging to other user accounts.
CVSS信息
N/A
漏洞类别
特权授予不正确