Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| erxes(npm) | 0 | 1.6.1 | N/A |
CVSS Metrics