NA

CVE-2023-46449

Published: 26/10/2023 Updated: 30/10/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.

Vulnerable Product Search on Vulmon Subscribe to Product

mayurik inventory management system 1.0

Github Repositories

CVE-2023-46449 Incorrect Access Control VIDEO POC LINK wwwyoutubecom/watch?v=H5QnsOKjs3s Sourcecodester Free and Open Source inventory management system v10 is vulnerable to Incorrect Access Control An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function STEPS TO REPRODUCE 1 Login to the user 1 2 v