漏洞标题
SourceCodester Online Railway Reservation System view_details.php存在访问控制漏洞
漏洞描述信息
在SourceCodester Online Railway Reservation System 1.0中发现了一个漏洞,并被分类为严重漏洞。该问题影响了文件/admin/inquiries/view_details.php中的某个未知处理过程。对参数id的操纵会导致访问控制不当。该攻击可以从远程发起。漏洞的利用方法已经公开,并可能被利用。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
漏洞类别
访问控制不恰当
漏洞标题
SourceCodester Online Railway Reservation System view_details.php access control
漏洞描述信息
A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/inquiries/view_details.php. The manipulation of the argument id leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
漏洞类别
访问控制不恰当
漏洞标题
Online Railway Reservation System 访问控制错误漏洞
漏洞描述信息
Online Railway Reservation System是adminastro个人开发者的一个在线铁路订票系统。 Online Railway Reservation System 1.0 版本存在访问控制错误漏洞,该漏洞源于/admin/inquiries/view_details.php页面中的id参数包含一个导致不当的访问控制问题。
CVSS信息
N/A
漏洞类别
授权问题