CVE-2021-37331
Summary
| CVE | CVE-2021-37331 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-04 14:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade License and viewing it, ID Cards and Trade Licenses of other vendors/users can be viewed by changing the URL. |
Risk And Classification
Problem Types: CWE-639
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bookingcore | Booking Core | 2.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Booking Core Vulnerabilities | Navid Kagalwalla | MISC | www.navidkagalwalla.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.