Executive brief
The Service Center platform by BankPro E-Service Technology contains a security flaw that allows logged-in users to view order details belonging to other customers. By manipulating specific web parameters, an attacker can bypass intended access controls to retrieve sensitive e-commerce transaction information. This could lead to the exposure of private customer data and business order history.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in the Service Center application developed by BankPro E-Service Technology. The flaw is located within a specific query function where the application fails to properly validate that the requesting user has permission to access the requested object. An authenticated remote attacker can exploit this by modifying parameters (such as order IDs) in web requests to retrieve sensitive e-commerce (EC) order details belonging to other users. The vulnerability has been patched server-side by the vendor, and no user action is required.
Affected products
- BankPro E-Service Technology Service Center
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory
- 2026-05-29: patched: Patched server-side by the vendor.