Security features bypass in Ingredients Stock Management System - #VU63854

 

Security features bypass in Ingredients Stock Management System - #VU63854

Published: May 31, 2022


Vulnerability identifier: #VU63854
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to improper authentication validation. A remote attacker can send a specially crafted HTTP POST request and takeover any registered Staff user account.


Affected software

Ingredients Stock Management System

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins