- **Title**: SourceCodester Gas Agency Management System 1.0 Improper Access Controls - **Description**: The SourceCodester Gas Agency Management System has an improper access control vulnerability. A normal authenticated user can perform administrative actions like creating new users, bookings, consumers, and cylinders by directly invoking privileged backend endpoints. The application uses only client-side UI restrictions to limit access to administrative functionality without server-side authorization checks. - **Source**: [https://github.com/Asim-QAZi/Improper-Access-Control-in-SourceCodester-Gas-Agency-Management-System](https://github.com/Asim-QAZi/Improper-Access-Control-in-SourceCodester-Gas-Agency-Management-System) - **User**: moasim (UID 93970) - **Submission Date**: 01/21/2026 12:26 PM - **Moderation Date**: 02/05/2026 08:21 PM - **Status**: Accepted - **VulDB Entry**: 344591 - **Points**: 20