bunyamindemir/vulnerability-disclosures

bunyamindemir/vulnerability-disclosures

Releases0
This is a repository for reporting and discussing vulnerabilities discovered in various software and systems. Our goal is to improve the security landscape by openly sharing information about vulnerabilities, fostering collaboration between security researchers, developers, and users to address and mitigate these issues.

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does not verify whether the user is logged in as an admin or even check for a session token at all.