PT-2023-20789 · Unknown · Sales Tracker Management System
CVE-2023-26774
·
Publicado
2023-04-10
·
Atualizado
2025-02-11
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sales Tracker Management System version 1.0
Description
An issue in the Sales Tracker Management System allows a remote attacker to access sensitive information via the "admin/reports" endpoint, specifically through the sales.php component.
Recommendations
For Sales Tracker Management System version 1.0, consider restricting access to the "admin/reports" endpoint and the sales.php component until a patch is available. As a temporary workaround, limit the functionality of the sales.php component to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sales Tracker Management System