PT-2023-20772 · Unknown · Sourcecodester Lost/Found Information System

Huutuanbg97

·

Published

2023-05-12

·

Updated

2024-05-17

·

CVE-2023-2670

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Lost and Found Information System version 1.0
Description A critical issue has been found, affecting the file "admin/?page=user/manage user". This leads to improper access controls, and the attack can be initiated remotely. The issue affects unknown code, allowing for potential exploitation.
Recommendations For SourceCodester Lost and Found Information System version 1.0, consider restricting access to the "admin/?page=user/manage user" endpoint until a patch is available. As a temporary workaround, review and limit user permissions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-2670

Affected Products

Sourcecodester Lost/Found Information System