Back

HIGH

Missing Authorization Vulnerability

Published Oct 4, 2024

Description

This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this vulnerability by placing or cancelling requests through API request body leading to unauthorized modification of requests belonging to the other users.

Affected products

Remediation

Vendor solution

Upgrade Client Dashboard to version 9.7.0

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-In
Published Oct 4, 2024
Updated Oct 4, 2024
Reserved Sep 30, 2024
CISA Vulnrichment
Updated Oct 4, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a