CVE-2023-0916
MEDIUMAuto Dealer Management System 1.0 - Improper Access Control in Users.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-0916. PoCs published by Muhammad Navaid Zafar Ansari.
AI-analyzed exploit summary This exploit demonstrates a broken access control vulnerability in Auto Dealer Management System 1.0, allowing low-privileged users to access and modify admin account details via unauthenticated access to the user list and password change functionality.
Description
A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adms/classes/Users.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221491.
Exploits (1)
This exploit demonstrates a broken access control vulnerability in Auto Dealer Management System 1.0, allowing low-privileged users to access and modify admin account details via unauthenticated access to the user list and password change functionality.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L