CVE-2024-44313

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tastyigniter:tastyigniter:3.7.6:*:*:*:*:*:*:*

History

02 Apr 2025, 12:30

Type Values Removed Values Added
First Time Tastyigniter tastyigniter
Tastyigniter
References () https://github.com/tastyigniter/TastyIgniter/blob/3.x/app/admin/controllers/Orders.php - () https://github.com/tastyigniter/TastyIgniter/blob/3.x/app/admin/controllers/Orders.php - Product
References () https://medium.com/@cnetsec/cve-2024-44313-incorrect-access-control-in-tastyigniter-3-7-6-01a73c548b74 - () https://medium.com/@cnetsec/cve-2024-44313-incorrect-access-control-in-tastyigniter-3-7-6-01a73c548b74 - Exploit
CPE cpe:2.3:a:tastyigniter:tastyigniter:3.7.6:*:*:*:*:*:*:*

25 Mar 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CWE CWE-284
Summary
  • (es) TastyIgniter 3.7.6 contiene una vulnerabilidad de control de acceso incorrecto en la función factura() dentro de Orders.php que permite a usuarios no autorizados acceder y generar facturas debido a la falta de controles de permisos.

18 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-18 15:15

Updated : 2025-04-02 12:30


NVD link : CVE-2024-44313

Mitre link : CVE-2024-44313

CVE.ORG link : CVE-2024-44313


JSON object : View

Products Affected

tastyigniter

  • tastyigniter
CWE
CWE-284

Improper Access Control