PT-2025-11602 · Unknown · Tastyigniter

Published

2025-03-18

·

Updated

2025-03-18

·

CVE-2024-44313

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions TastyIgniter version 3.7.6
Description The issue is related to an Incorrect Access Control problem in the invoice() function within Orders.php. This allows unauthorized users to access and generate invoices due to missing permission checks.
Recommendations For TastyIgniter version 3.7.6, consider disabling the invoice() function within Orders.php until a patch is available to prevent unauthorized access to invoices. Restrict access to the Orders.php module to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-44313
GHSA-GG2F-R4JH-VPMH

Affected Products

Tastyigniter