PT-2019-18969 · Unknown · Online Store System

Larry W. Cashdollar

·

Published

2019-10-01

·

Updated

2022-10-14

·

CVE-2019-8292

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Online Store System version 1.0
Description The issue concerns the delete product.php file in the Online Store System, which fails to verify if a user is authenticated or has administrative rights. This oversight allows for arbitrary product deletion.
Recommendations For Online Store System version 1.0, consider implementing authentication checks and verifying administrative rights in the delete product.php file to prevent unauthorized product deletion. As a temporary workaround, restrict access to the delete product.php file until a proper fix is implemented.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2019-8292

Affected Products

Online Store System