PT-2024-30045 · Unknown · Warehouse Inventory System

Topsky979

·

Published

2024-08-20

·

Updated

2024-08-21

·

CVE-2024-42583

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Warehouse Inventory System version 2.0
Description A Cross-Site Request Forgery (CSRF) issue in the delete user.php component allows attackers to escalate privileges, potentially leading to unauthorized user deletion.
Recommendations For Warehouse Inventory System version 2.0, patch immediately and validate user requests to prevent exploitation. As a temporary workaround, consider restricting access to the delete user.php component until a patch is applied.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-42583

Affected Products

Warehouse Inventory System