Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gg2f-r4jh-vpmh

Опубликовано: 18 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

TastyIgniter Has an Incorrect Access Control Vulnerability via invoice() Function

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.

Пакеты

Наименование

tastyigniter/tastyigniter

composer
Затронутые версииВерсия исправления

< 4.0.0

4.0.0

EPSS

Процентиль: 83%
0.01855
Низкий

8.1 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.1
nvd
11 месяцев назад

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.

EPSS

Процентиль: 83%
0.01855
Низкий

8.1 High

CVSS3

Дефекты

CWE-284