PT-2023-20772 · Unknown · Sourcecodester Lost/Found Information System

Huutuanbg97

·

Publicado

2023-05-12

·

Atualizado

2024-05-17

·

CVE-2023-2670

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Lost and Found Information System version 1.0
Description A critical issue has been found, affecting the file "admin/?page=user/manage user". This leads to improper access controls, and the attack can be initiated remotely. The issue affects unknown code, allowing for potential exploitation.
Recommendations For SourceCodester Lost and Found Information System version 1.0, consider restricting access to the "admin/?page=user/manage user" endpoint until a patch is available. As a temporary workaround, review and limit user permissions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-2670

Produtos afetados

Sourcecodester Lost/Found Information System