CVE-2023-31704

CRITICAL

Sourcecodester Online Computer and Laptop Store 1.0 - Incorrect Authorization

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-31704. PoCs published by d34dun1c02n.

AI-analyzed exploit summary This repository contains a detailed writeup for CVE-2023-31704, an Incorrect Access Control vulnerability in Sourcecodester Online Computer and Laptop Store 1.0. The vulnerability allows remote attackers to elevate privileges to administrator by manipulating a POST request to the Users.php endpoint.

Description

Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role.

Exploits (1)

nomisec WRITEUP
by d34dun1c02n · poc
https://github.com/d34dun1c02n/CVE-2023-31704

This repository contains a detailed writeup for CVE-2023-31704, an Incorrect Access Control vulnerability in Sourcecodester Online Computer and Laptop Store 1.0. The vulnerability allows remote attackers to elevate privileges to administrator by manipulating a POST request to the Users.php endpoint.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Sourcecodester Online Computer and Laptop Store 1.0
Auth required
Prerequisites: Default admin credentials (admin:admin&123) · Access to the admin login page · Intercepting proxy to capture/modify requests
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0095
EPSS Percentile 56.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
oretnom23/online_computer_and_laptop_store 1.0
Published Jul 13, 2023
Tracked Since Feb 18, 2026