An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Service_provider_management_system | Oretnom23 | 1.0 (including) | 1.0 (including) |