cve/2023/CVE-2023-1460.md

18 lines
917 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-1460](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1460)
![](https://img.shields.io/static/v1?label=Product&message=Online%20Pizza%20Ordering%20System&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%201.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-287%20Improper%20Authentication&color=brighgreen)
### Description
A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file admin/ajax.php?action=save_user of the component Password Change Handler. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The identifier VDB-223305 was assigned to this vulnerability.
### POC
#### Reference
- https://vuldb.com/?id.223305
#### Github
- https://github.com/karimhabush/cyberowl