PT-2019-18969 · Unknown · Online Store System

Larry W. Cashdollar

·

Publicado

2019-10-01

·

Atualizado

2022-10-14

·

CVE-2019-8292

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Online Store System version 1.0
Description The issue concerns the delete product.php file in the Online Store System, which fails to verify if a user is authenticated or has administrative rights. This oversight allows for arbitrary product deletion.
Recommendations For Online Store System version 1.0, consider implementing authentication checks and verifying administrative rights in the delete product.php file to prevent unauthorized product deletion. As a temporary workaround, restrict access to the delete product.php file until a proper fix is implemented.

Exploit

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-8292

Produtos afetados

Online Store System