CVE-2024-46293

Published
View on NVD ↗
CVSS v3
9.8
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT

Description

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does not verify whether the user is logged in as an admin or even check for a session token at all.

This is a repository for reporting and discussing vulnerabilities discovered in various software and systems. Our goal is to improve the security landscape by openly sharing information about vulnerabilities, fostering collaboration between security researchers, developers, and users to address and mitigate these issues.
GitHubGitHub