CVE-2023-46449

Severity
8.8HIGH
EPSS
0.3%
top 51.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 26

Description

Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-3qmc-vv7g-wccj: Sourcecodester Free and Open Source inventory management system v12023-10-26
CVEList
CVE-2023-46449: Sourcecodester Free and Open Source inventory management system v12023-10-26
CVE-2023-46449 (HIGH CVSS 8.8) | Sourcecodester Free and Open Source | cvebase.io