Back

CRITICAL

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control

Published Sep 30, 2024

Description

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does not verify whether the user is logged in as an admin or even check for a session token at all.

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 30, 2024
Updated Sep 30, 2024
Reserved Sep 11, 2024
CISA Vulnrichment
Updated Sep 30, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a