PT-2022-20142 · Unknown · Oretnom23 Automotive Shop Management System
Published
2022-05-26
·
Updated
2022-06-10
·
CVE-2022-30495
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
oretnom23 Automotive Shop Management System version 1.0
Description
The issue concerns a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), allowing attackers to perform vertical privilege escalation by changing the admin password. This is achieved through the
name id parameter.Recommendations
For oretnom23 Automotive Shop Management System version 1.0, consider restricting access to the
name id parameter to prevent unauthorized changes to the admin password until a fix is available. As a temporary workaround, limit the ability to change the admin password to minimize the risk of exploitation.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oretnom23 Automotive Shop Management System