CVE-2022-2019

HIGH

Prison Management System - Improper Authorization

Title source: rule
STIX 2.1

Description

A vulnerability classified as critical was found in SourceCodester Prison Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Users.php?f=save of the component New User Creation. The manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://vuldb.com/?id.201367

Scores

CVSS v3 7.3
EPSS 0.0020
EPSS Percentile 41.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-285
Status published
Products (1)
prison_management_system_project/prison_management_system 1.0
Published Jun 09, 2022
Tracked Since Feb 18, 2026