BankPro E-Service Technology Service Center Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing authenticated remote attackers to access other users' EC order details has been identified in the Service Center application developed by BankPro E-Service Technology. This Insecure Direct Object Reference vulnerability arises from the ability to modify parameters in specific query functions, thereby gaining unauthorized access to sensitive order information.

Impact

Exploitation of this vulnerability allows for unauthorized access to other users' EC order details.

Remediation

The vulnerability has been patched server-side, and users do not need to take any action.

Added: May 29, 2026, 7:18 AM
Updated: May 29, 2026, 7:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
5.2
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.