CVE-2024-8949

A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown part of the file /classes/Master.php of the component Cart Content Handler. The manipulation of the argument cart_id/id leads to improper ownership management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oretnom23:online_eyewear_shop:1.0:*:*:*:*:*:*:*

History

23 Sep 2024, 18:05

Type Values Removed Values Added
References () https://github.com/gurudattch/CVEs/edit/main/Sourcecodester-Online-Eyewear-shop-webiste-Broken-access-control.md - () https://github.com/gurudattch/CVEs/edit/main/Sourcecodester-Online-Eyewear-shop-webiste-Broken-access-control.md - Permissions Required
References () https://vuldb.com/?ctiid.277767 - () https://vuldb.com/?ctiid.277767 - Permissions Required
References () https://vuldb.com/?id.277767 - () https://vuldb.com/?id.277767 - Third Party Advisory
References () https://vuldb.com/?submit.409459 - () https://vuldb.com/?submit.409459 - Third Party Advisory
References () https://www.sourcecodester.com/ - () https://www.sourcecodester.com/ - Product
CVSS v2 : 6.5
v3 : 6.3
v2 : 6.5
v3 : 8.8
First Time Oretnom23 online Eyewear Shop
Oretnom23
CPE cpe:2.3:a:oretnom23:online_eyewear_shop:1.0:*:*:*:*:*:*:*

20 Sep 2024, 12:30

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad clasificada como crítica en SourceCodester Online Eyewear Shop 1.0. Afecta a una parte desconocida del archivo /classes/Master.php del componente Cart Content Handler. La manipulación del argumento cart_id/id provoca una gestión incorrecta de la propiedad. Es posible iniciar el ataque de forma remota. El exploit ha sido divulgado al público y puede ser utilizado.

17 Sep 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-17 19:15

Updated : 2024-09-23 18:05


NVD link : CVE-2024-8949

Mitre link : CVE-2024-8949

CVE.ORG link : CVE-2024-8949


JSON object : View

Products Affected

oretnom23

  • online_eyewear_shop
CWE
CWE-282

Improper Ownership Management