Automatic Question Paper Generator System firstname lastname id username password security bypass |
NAME
Automatic Question Paper Generator System firstname lastname id username password security bypass
- Platforms Affected:
Sourcecodester Automatic Question Paper Generator System 1.0 - Risk Level:
9.1 - Exploitability:
Proof of Concept - Consequences:
Bypass Security
DESCRIPTION
Automatic Question Paper Generator System could allow a remote attacker to bypass security restrictions, caused by an insecure direct object reference in the firstname, lastname, id, username, and password fields. An attacker could exploit this vulnerability to reset other users’ passwords.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Unavailable
MITIGATION
No remedy available as of March 14, 2022.
- Reference Link:
https://packetstormsecurity.com/files/166288 - Reference Link:
https://www.sourcecodester.com/php/15190/automatic-question-paper-generator-system-phpoop-free-source-code.html
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.