CVE Vulnerabilities

CVE-2022-42238

Direct Request ('Forced Browsing')

Published: Oct 11, 2022 | Modified: May 20, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

NameVendorStart VersionEnd Version
Merchandise_online_storeMerchandise_online_store_project1.0 (including)1.0 (including)

Potential Mitigations

References