CVE-2024-44314
Last modified
CVE-2024-44314 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. This flaw can be exploited remotely, leading to unauthorized order manipulation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tastyigniter | Tastyigniter | 3.7.6 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-44314?
How severe is CVE-2024-44314?
How do I fix CVE-2024-44314?
Are you affected by CVE-2024-44314?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
