CVE Vulnerabilities

CVE-2021-36560

Direct Request ('Forced Browsing')

Published: Nov 02, 2021 | Modified: Jul 12, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Phone_shop_sales_management_system Phone_shop_sales_management_system_project 1.0 (including) 1.0 (including)

Potential Mitigations

References