TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. This flaw can be exploited remotely, leading to unauthorized order manipulation.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-285 | |
Metrics |
cvssV3_1
|
Tue, 18 Mar 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. This flaw can be exploited remotely, leading to unauthorized order manipulation. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-18T00:00:00.000Z
Updated: 2025-03-21T15:00:15.296Z
Reserved: 2024-08-21T00:00:00.000Z
Link: CVE-2024-44314

Updated: 2025-03-21T14:58:50.351Z

Status : Awaiting Analysis
Published: 2025-03-18T15:15:53.847
Modified: 2025-03-21T15:15:41.497
Link: CVE-2024-44314

No data.