ZeroHour

CVE-2024-44313

PoC
CVSS 3.1
8.1 high
EPSS
<1%p52
Published
()
Modified
Description

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.

Vendors
tastyigniter
Products
tastyigniter
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.