Fiche vulnérabilité
CVE-2023-46449 : faille élevée mayurik inventory management system (CVSS 8.8)
Description
Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 26 oct. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- mayurik inventory management system