Event Management System userregister.php privilege escalation |
NAME
Event Management System userregister.php privilege escalation
- Platforms Affected:
Sourcecodester Event Management System 1.0 - Risk Level:
9.8 - Exploitability:
Proof of Concept - Consequences:
Gain Privileges
DESCRIPTION
Event Management System could allow a remote attacker to gain elevated privileges on the system, caused by lack of session validation in the userregister.php script. An attacker could exploit this vulnerability to register users with administrative permissions.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Unavailable
MITIGATION
No remedy available as of March 28, 2022.
- Reference Link:
https://packetstormsecurity.com/files/166478 - Reference Link:
https://www.sourcecodester.com/php/15238/event-management-system-project-php-source-code.html
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.