Code-Projects Online Shoe Store Improper Access Control Vulnerability

Vulnerability

A critical vulnerability has been identified in Code-Projects Online Shoe Store version 1.0, specifically within the file '/admin/index.php'. This vulnerability arises from broken access controls, allowing any user, including those unauthenticated, to gain administrative privileges and access the admin panel. The issue can be exploited remotely without any authentication.

Impact

Exploitation of this vulnerability allows unauthorized users to gain admin rights and access the administrative panel.

Reproduction

To reproduce this vulnerability, log in as a normal user and navigate to '/admin/index.php'. This action will grant admin privileges, allowing access to the admin panel.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
5.0
exploitability
9.5
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.