Improper access control in Restaurant Reservations - CVE-2022-0421
Published: December 8, 2022
Restaurant Reservations
Theme of the Crop
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions and change the payment status of arbitrary bookings. Furthermore, attacker can perform Cross-Site Scripting attacks against a logged-in admin viewing the failed payments.