SourceCodester Online Pizza Ordering System Password Change improper authentication
CVE-2023-1460
9.8CRITICAL
Summary
A security flaw has been identified in SourceCodester's Online Pizza Ordering System 1.0, located within the password change handler component. This vulnerability arises from improper authentication processes in the admin/ajax.php file, specifically with the action save_user. The nature of the flaw allows potential attackers to exploit this vulnerability remotely, which could compromise user accounts and sensitive data. Adequate measures should be taken to mitigate this risk and ensure robust authentication protocols are in place.
Affected Version(s)
Online Pizza Ordering System 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
WWesleywww (VulDB User)