CVE Vulnerabilities

CVE-2022-42238

Direct Request ('Forced Browsing')

Published: Oct 11, 2022 | Modified: Aug 08, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Merchandise_online_store Merchandise_online_store_project 1.0 (including) 1.0 (including)

Potential Mitigations

References