CVE-2024-44313
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Mar 18, 2025
Updated: Apr 2, 2025
CWE ID 284
Summary
CVE-2024-44313 is a newly discovered vulnerability affecting TastyIgniter version 3.7.6. This issue involves a misconfiguration in the invoice() function of Orders.php, where access control checks are inadequate. As a result, unauthorized users can bypass these checks and gain the ability to access and generate invoices, potentially resulting in data breaches or financial loss. This vulnerability emphasizes the importance of implementing strict access control measures to protect sensitive information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.