CVE-2024-8949: SourceCodester Online Eyewear Shop Cart Content Master.php improper ownership management
A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown part of the file /classes/Master.php of the component Cart Content Handler. The manipulation of the argument cartid/id leads to improper ownership management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8949?
CVE-2024-8949 is classified as a critical vulnerability.
How does CVE-2024-8949 affect the Online Eyewear Shop?
CVE-2024-8949 affects the Cart Content Handler in the Online Eyewear Shop by allowing improper ownership management through the manipulation of cart_id or id.
What is the affected version for CVE-2024-8949?
CVE-2024-8949 specifically affects SourceCodester Online Eyewear Shop version 1.0.
How can I mitigate CVE-2024-8949?
To mitigate CVE-2024-8949, it's essential to update the Online Eyewear Shop to a patched version that addresses ownership management issues.
Is CVE-2024-8949 exploitable remotely?
Yes, CVE-2024-8949 is likely exploitable remotely, allowing attackers to manipulate cart_id or id.