TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. This flaw can be exploited remotely, leading to unauthorized order manipulation.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Apr 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tastyigniter
Tastyigniter tastyigniter |
|
CPEs | cpe:2.3:a:tastyigniter:tastyigniter:3.7.6:*:*:*:*:*:*:* | |
Vendors & Products |
Tastyigniter
Tastyigniter tastyigniter |
Fri, 21 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-285 | |
Metrics |
cvssV3_1
|
Tue, 18 Mar 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. This flaw can be exploited remotely, leading to unauthorized order manipulation. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-21T15:00:15.296Z
Reserved: 2024-08-21T00:00:00.000Z
Link: CVE-2024-44314

Updated: 2025-03-21T14:58:50.351Z

Status : Analyzed
Published: 2025-03-18T15:15:53.847
Modified: 2025-04-02T12:29:56.447
Link: CVE-2024-44314

No data.