Sourcecodester Money Transfer Management System | CVE-2021-44582
NAME
Sourcecodester Money Transfer Management System
- Platforms Affected:
Sourcecodester Money Transfer Management System 1.0 - Risk Level:
8.8 - Exploitability:
Unproven - Consequences:
Gain Privileges
DESCRIPTION
Sourcecodester Money Transfer Management System could allow a remote authenticated attacker to gain elevated privileges on the system. By forced browsing any URL, an authenticated attacker could exploit this vulnerability to gain elevated privileges to the Admin role.
CVSS 3.0 Information
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Unavailable
MITIGATION
No remedy available as of June 10, 2022.
- Reference Link:
https://github.com/warmachine-57/CVE-2021-44582/blob/main/Privilege%20Escalation%20via%20Forced%20Browsing%20in%20Sourcecodester%20Money%20Transfer%20Management%20System - Reference Link:
https://www.sourcecodester.com/php/15015/money-transfer-management-system-send-money-businesses-php-free-source-code.html
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.