CVE-2024-46293
Published
CVSS v3
9.8
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT
Description
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does not verify whether the user is logged in as an admin or even check for a session token at all.
This is a repository for reporting and discussing vulnerabilities discovered in various software and systems. Our goal is to improve the security landscape by openly sharing information about vulnerabilities, fostering collaboration between security researchers, developers, and users to address and mitigate these issues.