CVE-2023-0963
HIGHSourceCodester Music Gallery Site 1.0 - Improper Access Control in Users.php POST Request Handler
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-0963. PoCs published by Muhammad Navaid Zafar Ansari.
AI-analyzed exploit summary This exploit demonstrates a broken access control vulnerability in Music Gallery Site v1.0, allowing unauthenticated users to create admin accounts via a POST request to Users.php. The vulnerability arises from missing authentication checks in Users.php and Master.php.
Description
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file Users.php of the component POST Request Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221633 was assigned to this vulnerability.
Exploits (1)
This exploit demonstrates a broken access control vulnerability in Music Gallery Site v1.0, allowing unauthenticated users to create admin accounts via a POST request to Users.php. The vulnerability arises from missing authentication checks in Users.php and Master.php.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L