A Missing Authorization vulnerability has been found in...
Moderate severity
Unreviewed
Published
May 28, 2025
to the GitHub Advisory Database
•
Updated May 28, 2025
Description
Published by the National Vulnerability Database
May 28, 2025
Published to the GitHub Advisory Database
May 28, 2025
Last updated
May 28, 2025
A Missing Authorization vulnerability has been found in DinoRANK. This
vulnerability allows an attacker to access invoices of any user via
accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there
is no access control. The pdf filename can be obtained via OSINT,
insecure network traffic or brute force.
References