CVE-2023-0963
SourceCodester Music Gallery Site POST Request Users.php access control
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file Users.php of the component POST Request Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221633 was assigned to this vulnerability.
Eine Schwachstelle wurde in SourceCodester Music Gallery Site 1.0 ausgemacht. Sie wurde als kritisch eingestuft. Betroffen davon ist ein unbekannter Prozess der Datei Users.php der Komponente POST Request Handler. Mittels dem Manipulieren mit unbekannten Daten kann eine improper access controls-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
Music Gallery Site version 1.0 suffers from a missing authentication vulnerability that allows for privilege escalation.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-02-22 CVE Reserved
- 2023-02-22 CVE Published
- 2023-04-06 First Exploit
- 2024-08-02 CVE Updated
- 2024-10-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-284: Improper Access Control
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.221633 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/51289 | 2023-04-06 | |
https://github.com/navaidzansari/CVE_Demo/blob/main/2023/Music%20Gallery%20Site%20-%20Broken%20Access%20Control.md | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Music Gallery Site Project Search vendor "Music Gallery Site Project" | Music Gallery Site Search vendor "Music Gallery Site Project" for product "Music Gallery Site" | 1.0 Search vendor "Music Gallery Site Project" for product "Music Gallery Site" and version "1.0" | - |
Affected
|