We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-38965



Assignermitre
Reserved2023-07-25
Published2023-11-03
Updated2024-09-05

Description

Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.

References

https://github.com/Or4ngm4n/vulnreability-code-review-php/blob/main/Lost%20and%20Found%20Information%20System%20v1.0.txt

http://packetstormsecurity.com/files/175077/Lost-And-Found-Information-System-1.0-Insecure-Direct-Object-Reference.html

cve.org CVE-2023-38965

nvd.nist.gov CVE-2023-38965

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-38965
Subscribe to our newsletter to learn more about our work.