Service Center developed by BankPro E-Service Technology...
High severity
Unreviewed
Published
May 29, 2026
to the GitHub Advisory Database
•
Updated May 29, 2026
Description
Published by the National Vulnerability Database
May 29, 2026
Published to the GitHub Advisory Database
May 29, 2026
Last updated
May 29, 2026
Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify the parameter of a specific query function to access other users' EC order details.
References