SingMR HouseRent Improper Access Control Vulnerability in AdminController

Vulnerability

A critical vulnerability exists in SingMR HouseRent version 1.0, specifically within the AdminController.java file. This issue arises from improper access controls, allowing unauthorized access to certain functionalities. The vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability leads to unauthorized access, allowing users to bypass normal authentication or authorization checks.

Reproduction

To reproduce this vulnerability, upload the application to a server and navigate to the '/toAdminHomePage' endpoint. The lack of proper permission verification in the AdminController will allow access without the necessary authorization.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.