H8 SSRMS Insecure Direct Object Reference

H8 SSRMS suffers from an insecure direct object reference vulnerability.


MD5 | eeb77367e260bec74f701163cf55a424

# Exploit Title: H8 SSRMS - 'id' IDOR
# Date: 01/31/2021
# Exploit Author: Mohammed Farhan
# Vendor Homepage: https://www.height8tech.com/
# Version: H8 SSRMS
# Tested on: Windows 10


Vulnerability Details
======================
Login to the application
Navigate to Payment Section and Click on Print button.
In QuotePrint.aspx, modify the id Parameter to View User details, Address,
Payments, Phonenumber and Email of other Users

Related Posts