Security features bypass in Ingredients Stock Management System - #VU63854
Published: May 31, 2022
Vulnerability identifier: #VU63854
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to improper authentication validation. A remote attacker can send a specially crafted HTTP POST request and takeover any registered Staff user account.
Affected software
Ingredients Stock Management System
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.