vendor:
Employee Task Management System
by:
Muhammad Navaid Zafar Ansari
7.5
CVSS
HIGH
Broken Authentication
287
CWE
Product Name: Employee Task Management System
Affected Version From: v1.0
Affected Version To: v1.0
Patch Exists: YES
Related CWE: CVE-2023-0905
CPE: 2.3:a:sourcecodester:employee_task_management_system:1.0:*:*:*:*:*:*
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=134911, https://www.infosecmatter.com/nessus-plugin-library/?id=125819, https://www.infosecmatter.com/nessus-plugin-library/?id=24906, https://www.infosecmatter.com/nessus-plugin-library/?id=134990, https://www.infosecmatter.com/nessus-plugin-library/?id=136472, https://www.infosecmatter.com/nessus-plugin-library/?id=79962, https://www.infosecmatter.com/nessus-plugin-library/?id=136920, https://www.infosecmatter.com/nessus-plugin-library/?id=134842, https://www.infosecmatter.com/nessus-plugin-library/?id=134754, https://www.infosecmatter.com/nessus-plugin-library/?id=134700
Platforms Tested: Windows 11
2023
Employee Task Management System v1.0 – Broken Authentication
Broken Authentication allows unauthenticated remote attacker to change password of all application users. On the vulnerable page, application isn't verifying the authentication/authorization mechanism. Due to that, all the parameters are vulnerable to broken authentication.
Mitigation:
To mitigate this vulnerability, the application should implement proper authentication and authorization mechanisms.