Логотип exploitDog
bind:CVE-2024-44314
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-44314

Количество 2

Количество 2

nvd логотип

CVE-2024-44314

11 месяцев назад

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. This flaw can be exploited remotely, leading to unauthorized order manipulation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w5h7-mw56-4v7x

11 месяцев назад

TastyIgniter Has an Incorrect Access Control Vulnerability

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-44314

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. This flaw can be exploited remotely, leading to unauthorized order manipulation.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-w5h7-mw56-4v7x

TastyIgniter Has an Incorrect Access Control Vulnerability

CVSS3: 6.5
0%
Низкий
11 месяцев назад

Уязвимостей на страницу