CVE-2024-44313

T

astyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.

Configurations

Configuration 1 (hide)

cpe:2.3:a:tastyigniter:tastyigniter:3.7.6:*:*:*:*:*:*:*

History

02 Apr 2025, 12:30

Type Values Removed Values Added
CPE cpe:2.3:a:tastyigniter:tastyigniter:3.7.6:*:*:*:*:*:*:*
First Time Tastyigniter
Tastyigniter tastyigniter
References () https://github.com/tastyigniter/TastyIgniter/blob/3.x/app/admin/controllers/Orders.php - () https://github.com/tastyigniter/TastyIgniter/blob/3.x/app/admin/controllers/Orders.php - Product
References () https://medium.com/@cnetsec/cve-2024-44313-incorrect-access-control-in-tastyigniter-3-7-6-01a73c548b74 - () https://medium.com/@cnetsec/cve-2024-44313-incorrect-access-control-in-tastyigniter-3-7-6-01a73c548b74 - Exploit

25 Mar 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
Summary
  • (es) TastyIgniter 3.7.6 contiene una vulnerabilidad de control de acceso incorrecto en la función factura() dentro de Orders.php que permite a usuarios no autorizados acceder y generar facturas debido a la falta de controles de permisos.
CWE CWE-284

18 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-18 15:15

Updated : 2025-04-02 12:30


NVD link : CVE-2024-44313

Mitre link : CVE-2024-44313

CVE.ORG link : CVE-2024-44313


JSON object : View

Products Affected
CWE
CWE-284

Improper Access Control