PT-2023-20772 · Unknown · Sourcecodester Lost/Found Information System
Huutuanbg97
·
Publicado
2023-05-12
·
Atualizado
2024-05-17
·
CVE-2023-2670
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SourceCodester Lost and Found Information System version 1.0
Description
A critical issue has been found, affecting the file "admin/?page=user/manage user". This leads to improper access controls, and the attack can be initiated remotely. The issue affects unknown code, allowing for potential exploitation.
Recommendations
For SourceCodester Lost and Found Information System version 1.0, consider restricting access to the "admin/?page=user/manage user" endpoint until a patch is available. As a temporary workaround, review and limit user permissions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sourcecodester Lost/Found Information System