CVE-2024-46293
CVE-2024-46293
Título es
CVE-2024-46293
Lun, 30/09/2024 – 15:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-46293
Descripción en
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does not verify whether the user is logged in as an admin or even check for a session token at all.
30/09/2024
30/09/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
Enviar en el boletín
Off