Title: SourceCodester Gas Agency Management System 1.0 Improper Access Controls Description: The SourceCodester Gas Agency Management System has an improper access control vulnerability. A normal authenticated user can perform administrative actions like creating new users, bookings, consumers, and cylinders by directly invoking privileged backend endpoints. The application uses only client-side UI restrictions to limit access to administrative functionality without server-side authorization checks. Source: https://github.com/Asim-QAZi/Improper-Access-Control-in-SourceCodester-Gas-Agency-Management-System User: moasim (UID 93970) Submission Date: 01/21/2026 12:26 PM Moderation Date: 02/05/2026 08:21 PM Status: Accepted VulDB Entry: 344591 Points: 20