CVE-2024-44313

HIGH8.1EPSS 1.2%

TastyIgniter Has an Incorrect Access Control Vulnerability via `invoice()` Function

發布日:2025/3/18修改日:2025/3/26

描述

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

參考連結(4)