PT-2021-21289 · Unknown · Phone Shop Sales Managements System
Published
2021-11-02
·
Updated
2022-07-12
·
CVE-2021-36560
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Phone Shop Sales Managements System using PHP with Source Code version 1.0
Description
The issue concerns an authentication bypass, which can lead to account takeover of the admin. This allows unauthorized access to the system, potentially compromising its security and data.
Recommendations
For Phone Shop Sales Managements System using PHP with Source Code version 1.0, consider implementing additional authentication measures to prevent bypass attempts, such as multi-factor authentication or more secure password hashing algorithms. As a temporary workaround, restrict access to admin accounts and monitor the system for any suspicious activity. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phone Shop Sales Managements System