PT-2019-18969 · Unknown · Online Store System
Larry W. Cashdollar
·
Publicado
2019-10-01
·
Atualizado
2022-10-14
·
CVE-2019-8292
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Online Store System version 1.0
Description
The issue concerns the delete product.php file in the Online Store System, which fails to verify if a user is authenticated or has administrative rights. This oversight allows for arbitrary product deletion.
Recommendations
For Online Store System version 1.0, consider implementing authentication checks and verifying administrative rights in the delete product.php file to prevent unauthorized product deletion. As a temporary workaround, restrict access to the delete product.php file until a proper fix is implemented.
Exploit
Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Online Store System