CVE-2023-0998

Severity
5.3MEDIUM
EPSS
0.8%
top 25.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 24

Description

A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file /alphaware/summary.php of the component Payment Handler. The manipulation of the argument amount leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221733 was assigned to this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:LExploitability: 3.9 | Impact: 2.5

🔴Vulnerability Details

2
GHSA
GHSA-75c8-27hp-p9fh: A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 12023-02-24
CVEList
SourceCodester Alphaware Simple E-Commerce System Payment summary.php access control2023-02-24
CVE-2023-0998 (MEDIUM CVSS 5.3) | A vulnerability classified as criti | cvebase.io