vendor:
Music Gallery Site
by:
Muhammad Navaid Zafar Ansari
9.8
CVSS
CRITICAL
Broken Access Control
284
CWE
Product Name: Music Gallery Site
Affected Version From: v1.0
Affected Version To: v1.0
Patch Exists: NO
Related CWE: CVE-2023-0963
CPE: a:sourcecodester:music_gallery_site:1.0
Platforms Tested: Windows 11
2023
Music Gallery Site v1.0 – Broken Access Control
Broken access control allows any remote attacker to create, update and delete the data of the application. Specifically, adding the admin users
Mitigation:
To mitigate this vulnerability, the application should implement proper access control mechanisms and validate user input. A thorough security review and testing should also be conducted.