Title: warehouse latest (git commit aaf29962ba407d22d991781de28796ee7b4670e4) Improper Access Controls Description: Sales and salesback endpoints do not enforce permissions. Attackers can forge sales or return records, delete legitimate records, and manipulate revenue/stock data, which impacts accounting accuracy and business reporting. These endpoints should enforce role-based access control, validate ownership/workflow state, and log all changes for auditability. Source: https://github.com/yeqifu/warehouse/issues/63 User: AliceS614 (UID 94277) Submission: 02/09/2026 05:58 AM (12 days ago) Moderation: 02/20/2026 10:01 AM (11 days later) Status: Accepted VulDB entry: 2347088 (yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4 Sales Endpoint SalesController.java addSales/updateSales/deleteSales access control) Points: 18