CVE-2024-57434: High severity macrozheng mall-tiny vulnerability
macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test user is made a super administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-57434?
CVE-2024-57434 is classified as a high severity vulnerability due to incorrect access control that could allow unauthorized users to gain super administrator privileges.
How do I fix CVE-2024-57434?
To fix CVE-2024-57434, ensure that proper access controls are implemented and review user roles to prevent unauthorized super administrator access.
Who is affected by CVE-2024-57434?
Users of macrozheng mall-tiny version 1.0.1 are specifically affected by CVE-2024-57434 due to its default import of users and role assignments.
What could happen if CVE-2024-57434 is exploited?
Exploitation of CVE-2024-57434 could allow an attacker to gain super administrator access, potentially resulting in unauthorized actions and data breaches.
Is there a patch available for CVE-2024-57434?
As of now, there is no specific patch mentioned for CVE-2024-57434, so implementing access control measures is critical.