Description
An issue was discovered in hitshop through 2014-07-15. There is an elevation-of-privilege vulnerability (that allows control over the whole web site) via the admin.php/user/add URI because a storekeeper account (which is supposed to have only privileges for commodity management) can add an administrator account.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-11528 | An issue was discovered in hitshop through 2014-07-15. There is an elevation-of-privilege vulnerability (that allows control over the whole web site) via the admin.php/user/add URI because a storekeeper account (which is supposed to have only privileges for commodity management) can add an administrator account. |
References
| Link | Providers |
|---|---|
| https://github.com/liu946/hitshop/issues/1 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:44:20.704Z
Reserved: 2018-12-04T00:00:00.000Z
Link: CVE-2018-19853
No data.
Status : Modified
Published: 2018-12-04T09:29:00.883
Modified: 2024-11-21T03:58:41.167
Link: CVE-2018-19853
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD