Incorrect access control in the component /index.php?mod...
Moderate severity
Unreviewed
Published
Jun 27, 2023
to the GitHub Advisory Database
•
Updated Dec 5, 2024
Description
Published by the National Vulnerability Database
Jun 27, 2023
Published to the GitHub Advisory Database
Jun 27, 2023
Last updated
Dec 5, 2024
Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse departments and usernames.
References