Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.
References
Link Resource
https://github.com/sajaljat/CVE-2023-46449/tree/main Exploit Third Party Advisory
https://www.youtube.com/watch?v=H5QnsOKjs3s Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-10-26T00:00:00

Updated: 2023-10-26T14:54:49.950956

Reserved: 2023-10-23T00:00:00


Link: CVE-2023-46449

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-26T15:15:09.257

Modified: 2023-10-30T15:55:58.057


Link: CVE-2023-46449

JSON object: View

cve-icon Redhat Information

No data.

CWE