TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. This flaw can be exploited remotely, leading to unauthorized order manipulation.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Apr 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tastyigniter
Tastyigniter tastyigniter |
|
| CPEs | cpe:2.3:a:tastyigniter:tastyigniter:3.7.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Tastyigniter
Tastyigniter tastyigniter |
Fri, 21 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 | |
| Metrics |
cvssV3_1
|
Tue, 18 Mar 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. This flaw can be exploited remotely, leading to unauthorized order manipulation. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-03-18T00:00:00.000Z
Updated: 2025-03-21T15:00:15.296Z
Reserved: 2024-08-21T00:00:00.000Z
Link: CVE-2024-44314
Updated: 2025-03-21T14:58:50.351Z
Status : Analyzed
Published: 2025-03-18T15:15:53.847
Modified: 2025-04-02T12:29:56.447
Link: CVE-2024-44314
No data.