CyberRota Analysis
AI-GeneratedA vulnerability exists in the Admin Handler component of Abdurrab5's online makeup store, specifically in the confirm_logged_in/confirm_user function, which suffers from missing authorization due to improper handling of the adminid argument. This flaw allows remote attackers to exploit the system, potentially gaining unauthorized access to administrative functions. Organizations using this product should prioritize immediate remediation to mitigate the risk of exploitation, especially given the public disclosure of the vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the component Admin Handler. Such manipulation of the argument adminid leads to missing authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure.