CVE-2023-0905
SourceCodester Employee Task Management System changePasswordForEmployee.php improper authentication
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file changePasswordForEmployee.php. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-221454 is the identifier assigned to this vulnerability.
Es wurde eine kritische Schwachstelle in SourceCodester Employee Task Management System 1.0 entdeckt. Betroffen hiervon ist ein unbekannter Ablauf der Datei changePasswordForEmployee.php. Mit der Manipulation mit unbekannten Daten kann eine improper authentication-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-02-18 CVE Reserved
- 2023-02-18 CVE Published
- 2023-04-06 First Exploit
- 2024-08-02 CVE Updated
- 2024-09-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Employee Task Management System Project Search vendor "Employee Task Management System Project" | Employee Task Management System Search vendor "Employee Task Management System Project" for product "Employee Task Management System" | 1.0 Search vendor "Employee Task Management System Project" for product "Employee Task Management System" and version "1.0" | - |
Affected
|