CVE Vulnerabilities

CVE-2022-42238

Direct Request ('Forced Browsing')

Published: Oct 11, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.

Weakness 

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software 

Name Vendor Start Version End Version
Merchandise_online_store Merchandise_online_store_project 1.0 (including) 1.0 (including)

Potential Mitigations 

References