vendor:
Online Voting System
by:
Giulio Comi
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: Online Voting System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: CVE-2018-6180
CPE: a:themashabrand:online_voting_system:1.0
Platforms Tested: Web
2018
Online Voting System – Authentication Bypass
A flaw in the profile section of Online Voting System allows an unauthenticated user to set an arbitrary password for accounts registered in the application. The application does not check the validity of the session cookie and updates the password and other fields of a user based on an incremental identifier and without requiring the current valid password for target account.
Mitigation:
The vendor should implement proper authentication mechanisms and ensure that session cookies are validated before allowing any updates to user profiles.