The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL parameters.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.twcert.org.tw/tw/cp-132-5296-cbf80-1.html |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T19:51:09.107Z
Reserved: 2021-10-12T00:00:00
Link: CVE-2021-42337

No data.

Status : Modified
Published: 2021-11-16T02:15:06.787
Modified: 2024-11-21T06:27:38.103
Link: CVE-2021-42337

No data.