SourceCodester Inventory Management System Password edit_update.php access control
CVE-2023-4183
9.8CRITICAL
Summary
An access control vulnerability has been identified in the SourceCodester Inventory Management System 1.0. This flaw, located in the edit_update.php file within the Password Handler component, allows for the manipulation of the user_id argument, resulting in improper access controls. Attackers can exploit this vulnerability remotely, leading to unauthorized actions within the system.
Affected Version(s)
Inventory Management System 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
mikel22 (VulDB User)