Script And Tools | Online-Travling-System | Broken Access Control In /admin/viewpackage.php
Hi All, I am Maloy Roy Orko. Recently in one of my pentest research, I found a Online-Travling-System application By Script And Tools which is an open source Online-Travling-System. It is made with PHP, MYSQL, JAVASCRIPT. Curious to explore its functionalities, I downloaded and set it up in my local system. After fiddling with the source code, I found that it did not have any kind of Proper Access Management in /admin/viewpackage.php file. This file cam be accessed by anyone even without logging in! It can lead into: Malware Distribution Unauthorized Access Data Breach Web Shell Installation Reputation Damage The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too.Thats why I am trying to inform everyone about this. Title of the Vulnerability: Script And Tools | Online-Travling-System | Broken Access Control In /admin/viewpackage.php Vulnerability Class : Broken Acce...