BankPro E-Service Technology Service Center Insecure Direct Object Reference Vulnerability
Vulnerability
A vulnerability allowing authenticated remote attackers to access other users' EC order details has been identified in the Service Center application developed by BankPro E-Service Technology. This Insecure Direct Object Reference vulnerability arises from the ability to modify parameters in specific query functions, thereby gaining unauthorized access to sensitive order information.
Impact
Exploitation of this vulnerability allows for unauthorized access to other users' EC order details.
Remediation
The vulnerability has been patched server-side, and users do not need to take any action.
Added: May 29, 2026, 7:18 AM
Updated: May 29, 2026, 7:18 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.3exploitability
5.2remediation
0.0relevance
9.7threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
