漏洞标题
SourceCodester 在线 Pizza ordering System 密码更改不当身份验证
漏洞描述信息
源代码艺人在线披萨订购系统密码更改不当身份验证
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
SourceCodester Online Pizza Ordering System Password Change improper authentication
漏洞描述信息
A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file admin/ajax.php?action=save_user of the component Password Change Handler. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The identifier VDB-223305 was assigned to this vulnerability.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
漏洞类别
认证机制不恰当
漏洞标题
Online Pizza Ordering System 授权问题漏洞
漏洞描述信息
Online Pizza Ordering System是Carlo Montero个人开发者的一个在线比萨订购系统。 SourceCodester Online Pizza Ordering System 1.0版本存在授权问题漏洞,该漏洞源于组件Password Change Handler中的 admin/ajax.php?action=save_user存在安全问题, 导致不正确的身份验证。
CVSS信息
N/A
漏洞类别
授权问题