{"api_version":"1","generated_at":"2026-07-24T03:29:11+00:00","cve":"CVE-2021-42337","urls":{"html":"https://cve.report/CVE-2021-42337","api":"https://cve.report/api/cve/CVE-2021-42337.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-42337","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-42337"},"summary":{"title":"CVE-2021-42337","description":"The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL parameters.","state":"PUBLIC","assigner":"cve@cert.org.tw","published_at":"2021-11-16 02:15:00","updated_at":"2022-08-09 14:40:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://www.twcert.org.tw/tw/cp-132-5296-cbf80-1.html","name":"https://www.twcert.org.tw/tw/cp-132-5296-cbf80-1.html","refsource":"MISC","tags":[],"title":"TWCERT/CC台灣電腦網路危機處理暨協調中心-艾富資訊 出納帳務管理系統 - Improper Authorization","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-42337","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-42337","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"42337","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aifu","cpe5":"cashier_accounting_management_system","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"AKA":"TWCERT/CC","ASSIGNER":"cve@cert.org.tw","DATE_PUBLIC":"2021-11-16T01:34:00.000Z","ID":"CVE-2021-42337","STATE":"PUBLIC","TITLE":"TVN-202110009"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"CASH","version":{"version_data":[{"version_affected":"?","version_value":"0"}]}}]},"vendor_name":" AIFU Information Technology Co."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL parameters."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-285 Improper Authorization"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://www.twcert.org.tw/tw/cp-132-5296-cbf80-1.html","name":"https://www.twcert.org.tw/tw/cp-132-5296-cbf80-1.html"}]},"solution":[{"lang":"eng","value":"Contact tech support from AIFU Information Technology Co."}],"source":{"advisory":"TVN-202110009","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2021-11-16 02:15:00","lastModifiedDate":"2022-08-09 14:40:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:aifu:cashier_accounting_management_system:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"42337","Ordinal":"218302","Title":"CVE-2021-42337","CVE":"CVE-2021-42337","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"42337","Ordinal":"1","NoteData":"The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL parameters.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"42337","Ordinal":"2","NoteData":"2021-11-15","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"42337","Ordinal":"3","NoteData":"2021-11-15","Type":"Other","Title":"Modified"}]}}}