CVE-2023-38965
CRITICALLost and Found Information System 1.0 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-38965. PoCs published by Or4nG.M4N.
AI-analyzed exploit summary This exploit demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Lost and Found Information System v1.0, allowing an attacker to overwrite user account details (including password) by sending a crafted POST request to the Users.php endpoint.
Description
Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.
Exploits (1)
This exploit demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Lost and Found Information System v1.0, allowing an attacker to overwrite user account details (including password) by sending a crafted POST request to the Users.php endpoint.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H