PT-2024-30038 · Unknown · Warehouse Inventory System

Topsky979

·

Published

2024-08-20

·

Updated

2024-08-21

·

CVE-2024-42577

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Warehouse Inventory System version 2.0
Description A Cross-Site Request Forgery (CSRF) in the component add product.php of Warehouse Inventory System allows attackers to escalate privileges.
Recommendations For Warehouse Inventory System version 2.0, consider implementing proper CSRF token validation in the add product.php component to prevent privilege escalation attacks. As a temporary workaround, restrict access to the add product.php component until a patch is available.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-42577

Affected Products

Warehouse Inventory System