This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this vulnerability could allow an authenticated remote attacker to modify information belonging to other user accounts.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 14 Feb 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this vulnerability could allow an authenticated remote attacker to modify information belonging to other user accounts. | |
Title | Insufficient Authorization Vulnerability in RupeeWeb trading platform | |
Weaknesses | CWE-266 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-In
Published: 2025-02-14T11:32:30.662Z
Updated: 2025-02-14T15:05:58.825Z
Reserved: 2025-02-12T11:42:37.480Z
Link: CVE-2025-26523

Updated: 2025-02-14T15:05:53.840Z

Status : Received
Published: 2025-02-14T12:15:29.723
Modified: 2025-02-14T12:15:29.723
Link: CVE-2025-26523

No data.