SourceCodester Web-Based Pharmacy Product Management System Improper Authorization Vulnerability
Vulnerability
A vulnerability exists in SourceCodester Web-Based Pharmacy Product Management System version 1.0, specifically in the add_admin.php file. This vulnerability allows for improper authorization, enabling authenticated users to access administrative functions without the necessary privileges. The issue can be exploited remotely.
Impact
Exploitation of this vulnerability allows low-privileged users to gain administrative rights, potentially leading to a full compromise of the application's administrative controls.
Reproduction
To reproduce this vulnerability, log in with an administrator account and create a normal user account. After logging out, log in with the newly created account and navigate directly to the add_admin.php endpoint. The page will load without restrictions, allowing the user to create a new admin account.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
