Vulnerability Description
TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tastyigniter | Tastyigniter | 3.7.6 |
Related Weaknesses (CWE)
References
- https://github.com/tastyigniter/TastyIgniter/blob/3.x/app/admin/controllers/OrdeProduct
- https://medium.com/@cnetsec/cve-2024-44313-incorrect-access-control-in-tastyigniExploit
FAQ
What is CVE-2024-44313?
CVE-2024-44313 is a vulnerability with a CVSS score of 8.1 (HIGH). TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permiss...
How severe is CVE-2024-44313?
CVE-2024-44313 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-44313?
Check the references section above for vendor advisories and patch information. Affected products include: Tastyigniter Tastyigniter.