PT-2023-32772 · Unknown · Codeastro Pos/Inventory Management System

Kerkroups

·

Publicado

2023-12-13

·

Atualizado

2024-05-17

·

CVE-2023-6773

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CodeAstro POS and Inventory Management System version 1.0
Description A vulnerability has been found in the system, allowing for improper access controls. The issue is related to the manipulation of the account type argument with the input Admin in the unknown functionality of the file /accounts con/register account of the component User Creation Handler. This can be exploited remotely.
Recommendations For CodeAstro POS and Inventory Management System version 1.0, as a temporary workaround, consider restricting access to the /accounts con/register account file to minimize the risk of exploitation. Avoid using the account type argument with the input Admin in the affected component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-6773

Produtos afetados

Codeastro Pos/Inventory Management System