CVE-2023-0916 EXPLOIT
6.3
MEDIUM · CVSS 3.1 · EPSS 3.1% (pctl 87)
Patch early
A public exploit exists.
Description
A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adms/classes/Users.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221491.
Scoring
| CVSS | 6.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 3.07% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-284 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-02-19 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| auto dealer management system project | auto dealer management system |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Auto Dealer Management System 1.0 - Broken Access Control Exploit | 2023-04-06 |
References
- https://github.com/navaidzansari/CVE_Demo/blob/main/2023/Auto%20Dealer%20Management%20System%20-%20Broken%20Access%20Control.md
- https://vuldb.com/?ctiid.221491
- https://vuldb.com/?id.221491
- https://github.com/navaidzansari/CVE_Demo/blob/main/2023/Auto%20Dealer%20Management%20System%20-%20Broken%20Access%20Control.md
- https://vuldb.com/?ctiid.221491
- https://vuldb.com/?id.221491
→ the Explorer · watch your stack · NVD