PT-2024-31948 · Sourcecodester · Sourcecodester Online Medicine Ordering System

CVE-2024-46293

·

Published

2024-09-30

·

Updated

2024-10-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Online Medicine Ordering System version 1.0
Description The issue is related to Incorrect Access Control, where there is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does not verify whether the user is logged in as an admin or even check for a session token at all.
Recommendations For Sourcecodester Online Medicine Ordering System version 1.0, consider implementing proper authorization checks for admin operations to prevent unauthorized access. As a temporary workaround, restrict access to admin-level actions until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-46293

Affected Products

Sourcecodester Online Medicine Ordering System