Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their account.
https://www.e-connectsolutions.com
https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2024-56114