
Proof-of-concept exploit for CVE-2023-31704: Incorrect access control in Sourcecodester Online Computer and Laptop Store 1.0 allows remote privilege escalation to administrator via crafted POST request.
[description] Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role.
[Vulnerability Type] Incorrect Access Control
[Vendor of Product] Sourcecodster
[Affected Product Code Base] Online Computer and Laptop Store - 1.0
[Affected Component] https://php-ocls/classes/Users.php?f=save
[Attack Type] Remote
[Impact Escalation of Privileges] true
[CVE Impact Other] All administrative functions are exposed allowing an attacker to modify the site. This includes modification of purchase prices for products and direct modification of the site itself to include
[Attack Vectors]
[Reference] https://www.sourcecodester.com/php/16397/online-computer-and-laptop-store-using-php-and-mysql-source-code-free-download.html https://www.sourcecodester.com/sites/default/files/download/oretnom23/php-ocls.zip
[Discoverer] William David Mathisen (d34dun1c02n)