CVE-2024-44313
Essential information
- Published
- 18/03/2025 15:15
- Modified
- 18/03/2025 15:15
- Author
- —
- Creator
- —
- CISA KEV
- No
- CWE
- —
- CVSS vector
- — — —
Description
TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.
NVD status
- Status
- Received — CVE has been recently published to the CVE List and has been received by the NVD.
- Source
- [email protected]
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| tastyigniter / tastyigniter | cpe:2.3:a:tastyigniter:tastyigniter:3.7.6:*:*:*:*:*:*:* |