- **Title**: SourceCodester Gas Agency Management System 1.0 Improper Access Controls - **Description**: The SourceCodester Gas Agency Management System contains an improper access control vulnerability. A regular authenticated user can perform administrative actions such as creating new users, bookings, consumers, and cylinders by directly invoking privileged backend endpoints. The application relies solely on client-side UI restrictions to limit access to administrative features, without implementing server-side authorization checks. - **Source**: [https://github.com/Asim-QAZi/Improper-Access-Control-in-SourceCodester-Gas-Agency-Management-System](https://github.com/Asim-QAZi/Improper-Access-Control-in-SourceCodester-Gas-Agency-Management-System) - **User**: moasim (UID 93970) - **Submission Date**: 01/21/2026 12:26 PM - **Moderation Date**: 02/05/2026 08:21 PM - **Status**: Accepted - **VulDB Entry**: 344591 - **Points**: 20