PT-2020-15638 · Projectworlds · Projectsworlds Online Book Store Php
Published
2020-08-31
·
Updated
2021-04-23
·
CVE-2020-24115
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
projectworlds Online Book Store version 1.0
Description
The issue is related to the use of hard-coded credentials in the source code, which can lead to unauthorized access to the admin panel.
Recommendations
For projectworlds Online Book Store version 1.0, remove the hard-coded credentials from the source code to prevent unauthorized access to the admin panel.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Projectsworlds Online Book Store Php