PT-2019-18969 · Unknown · Online Store System
Larry W. Cashdollar
·
Published
2019-10-01
·
Updated
2022-10-14
·
CVE-2019-8292
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Online Store System version 1.0
Description
The issue concerns the delete product.php file in the Online Store System, which fails to verify if a user is authenticated or has administrative rights. This oversight allows for arbitrary product deletion.
Recommendations
For Online Store System version 1.0, consider implementing authentication checks and verifying administrative rights in the delete product.php file to prevent unauthorized product deletion. As a temporary workaround, restrict access to the delete product.php file until a proper fix is implemented.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Online Store System