GHSA-7rhv-xm4q-wh42
HIGHCVE-2024-57190Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.
- Affected
- < 1.6.1
- Fixed in
- 1.6.1
- Weakness
- CWE-284
- Published
- 2025-06-10
- Source
- github