Cross-Site Request Forgery in Online Food Ordering System by Project Worlds
CVE-2023-27073

6.5MEDIUM

What is CVE-2023-27073?

A Cross-Site Request Forgery (CSRF) vulnerability exists in Online Food Ordering System v1.0, allowing attackers to execute unauthorized commands on behalf of authenticated users. By sending a maliciously crafted POST request, an attacker can modify user details and credentials without proper consent. This vulnerability highlights the importance of implementing anti-CSRF tokens to safeguard user data and maintain the integrity of the application. To mitigate risks, developers should ensure secure coding practices and regularly update software components.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.