PT-2023-20789 · Unknown · Sales Tracker Management System

CVE-2023-26774

·

Published

2023-04-10

·

Updated

2025-02-11

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sales Tracker Management System version 1.0
Description An issue in the Sales Tracker Management System allows a remote attacker to access sensitive information via the "admin/reports" endpoint, specifically through the sales.php component.
Recommendations For Sales Tracker Management System version 1.0, consider restricting access to the "admin/reports" endpoint and the sales.php component until a patch is available. As a temporary workaround, limit the functionality of the sales.php component to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-26774

Affected Products

Sales Tracker Management System