7.5
CVSSv3

CVE-2023-0905

Published: 18/02/2023 Updated: 17/05/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file changePasswordForEmployee.php. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-221454 is the identifier assigned to this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

employee task management system project employee task management system 1.0

Exploits

Employee Task Management System version 10 suffers from a privilege escalation vulnerability due to a broken access control where a lower privileged user's cookie can be leveraged to takeover an administrative account ...

Github Repositories

Reproduction de la vulnerabilité d'authentification brisée sur Employee-Task-Management-System-v1.0

Employee-Task-Management-System-v10---Broken-Authentication Reproduction de la vulnerabilité d'authentification brisée sur Employee-Task-Management-System-v10 Exploit Title: Employee Task Management System v10 - Broken Authentication Exploit Author: Muhammad Navaid Zafar Ansari Date: 17 February 2023 CVE Assigned: CVE-2023-0905 mitreorg, nvdnistorg Aut