CVE-2024-44313

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tastyigniter:tastyigniter:3.7.6:*:*:*:*:*:*:*

History

02 Apr 2025, 12:30

Type Values Removed Values Added
First Time Tastyigniter tastyigniter
Tastyigniter
CPE cpe:2.3:a:tastyigniter:tastyigniter:3.7.6:*:*:*:*:*:*:*
References () https://github.com/tastyigniter/TastyIgniter/blob/3.x/app/admin/controllers/Orders.php - () https://github.com/tastyigniter/TastyIgniter/blob/3.x/app/admin/controllers/Orders.php - Product
References () https://medium.com/@cnetsec/cve-2024-44313-incorrect-access-control-in-tastyigniter-3-7-6-01a73c548b74 - () https://medium.com/@cnetsec/cve-2024-44313-incorrect-access-control-in-tastyigniter-3-7-6-01a73c548b74 - Exploit

25 Mar 2025, 19:15

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
Summary
  • (es) TastyIgniter 3.7.6 contiene una vulnerabilidad de control de acceso incorrecto en la función factura() dentro de Orders.php que permite a usuarios no autorizados acceder y generar facturas debido a la falta de controles de permisos.

18 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-18 15:15

Updated : 2025-04-02 12:30


NVD link : CVE-2024-44313

Mitre link : CVE-2024-44313

CVE.ORG link : CVE-2024-44313


JSON object : View

Products Affected

tastyigniter

  • tastyigniter
CWE
CWE-284

Improper Access Control