Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicious user bypass authentication and obtain sensitive information.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://github.com/projectworldsofficial/online-book-store-project-in-php/issues/14 | third party advisory exploit |
https://cwe.mitre.org/data/definitions/287.html | third party advisory |