PoC Index

CVE-2023-46449

HIGH 8.8EPSS 0.8%

Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.76% chance of exploitation in the next 30 days, 53th percentile
Published
2023-10-26
Updated
2024-09-12

Proof-of-concept exploits (2)

References

Related