CVE-2023-0905
HIGHSourceCodester Employee Task Management System 1.0 - Improper Authentication via changePasswordForEmployee.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-0905. PoCs published by Muhammad Navaid Zafar Ansari.
AI-analyzed exploit summary This exploit demonstrates a broken authentication vulnerability in Employee Task Management System v1.0, allowing unauthenticated attackers to change passwords for any user by manipulating the user_id parameter in a POST request to changePasswordForEmployee.php.
Description
A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file changePasswordForEmployee.php. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-221454 is the identifier assigned to this vulnerability.
Exploits (1)
This exploit demonstrates a broken authentication vulnerability in Employee Task Management System v1.0, allowing unauthenticated attackers to change passwords for any user by manipulating the user_id parameter in a POST request to changePasswordForEmployee.php.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L