CVE-2024-9082

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Sep 22, 2024
Updated: Sep 27, 2024
CWE ID 285
CWE ID 863

Summary

CVE-2024-9082 is a critical vulnerability affecting SourceCodester Online Eyewear Shop version 1.0, specifically in the User Creation Handler component found in the file /Users.php with the argument type manipulation. This flaw allows for improper authorization, potentially enabling attackers to exploit the system remotely without requiring user interaction. The integrity and confidentiality impacts are rated low, but organizations should be aware of the potential risks associated with unauthorized access. To remediate this issue, it is advised to apply updates or patches provided by the vendor as soon as they are available. Public disclosure of this vulnerability increases its likelihood of exploitation, making prompt action essential for protecting organizational assets.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share