Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Unsafe Object Reference (IDOR) vulnerability in Stel Order
Vulnerability Description
Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation of the ‘employeeID’ parameter. An authenticated attacker could exploit this vulnerability to access information about any employee (first names, last names, roles, job titles, and vacation records, among others) by modifying that identifier in requests sent to the server.
CVSS Information
N/A
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
STEL Order 安全漏洞
Vulnerability Description
STEL Order是西班牙STEL公司的一个面向中小企业的ERP、CRM与在线计费管理平台。 STEL Order 3.25.1及之前版本存在安全漏洞,该漏洞源于对employeeID参数操作不当,可能导致经过身份验证的攻击者访问任何员工的信息。
CVSS Information
N/A
Vulnerability Type
N/A