Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Apr 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oretnom23
Oretnom23 online Medicine Ordering System |
|
| CPEs | cpe:2.3:a:oretnom23:online_medicine_ordering_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Oretnom23
Oretnom23 online Medicine Ordering System |
Mon, 30 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Online Medicine Ordering System Project
Online Medicine Ordering System Project online Medicine Ordering System |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:online_medicine_ordering_system_project:online_medicine_ordering_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Online Medicine Ordering System Project
Online Medicine Ordering System Project online Medicine Ordering System |
|
| Metrics |
cvssV3_1
|
Mon, 30 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does not verify whether the user is logged in as an admin or even check for a session token at all. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-30T18:51:51.659Z
Reserved: 2024-09-11T00:00:00.000Z
Link: CVE-2024-46293
Updated: 2024-09-30T18:51:45.857Z
Status : Analyzed
Published: 2024-09-30T15:15:06.123
Modified: 2025-04-28T18:07:39.903
Link: CVE-2024-46293
No data.
OpenCVE Enrichment
No data.