SourceCodester Online Pizza Ordering System POST Parameter ajax.php delete_category missing authentication
CVE-2023-0906
9.8CRITICAL
What is CVE-2023-0906?
A missing authentication vulnerability exists in the SourceCodester Online Pizza Ordering System version 1.0, specifically in the 'delete_category' function of the ajax.php file. This flaw allows unauthenticated users to invoke the function, potentially leading to unauthorized deletion of categories. Attackers can exploit this issue remotely, making it imperative for users and administrators of the system to take immediate action to secure their applications.
Affected Version(s)
Online Pizza Ordering System 1.0