Simbarashe Financial Services version 2.9.0 suffers from an insecure direct object reference vulnerability.