TastyIgniter
cpe:2.3:a:tastyigniter:tastyigniter:*:*:*:*:*:*:*
- 3.7.6
An incorrect access control vulnerability has been identified in TastyIgniter version 3.7.6. The issue resides in the invoice() function within Orders.php, where missing permission checks allow unauthorized users to access and generate invoices.
Exploitation of this vulnerability allows unauthorized users to access and generate invoices, potentially leading to unauthorized financial transactions or manipulation of order records.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.