CVE-2024-8949
Vendor: Sourcecodester [https://www.sourcecodester.com/php/16089/online-eyewear-shop-website-using-php-and-mysql-free-download.html]
Reference: https://github.com/gurudattch/
Product: Online Eyewear Shop Version: 1.0
Vulnerability Overview:
The Online Eyewear Shop version 1.0, developed by Sourcecodester, is vulnerable to a cart ID,ID manipulation vulnerability. This vulnerability allows an attacker to add or delete unwanted items to other users' carts by modifying the cart ID.
Vulnerability Details:
- Attack Vector: An attacker can exploit this vulnerability by tampering with the cart ID, ID which is likely stored in a cookie or a parameter in the URL.
- Impact: An attacker can add or delete items from other users' carts, leading to unwanted changes to their shopping carts. This can result in financial losses for the users and damage to the reputation of the Online Eyewear Shop.
- Exploitation: An attacker can exploit this vulnerability by intercepting and modifying the cart ID, allowing them to access and manipulate other users' carts.
Exploitaion
- Login with User1 go add some item in cart and click on cart
- Turn on BurpSuite and intercept this request
- Click on + to increase quantity

- Change the Cart_id of user1 to user2's cart id logout and login with User2 Observer the Item added to the Users2's Cart

Similarly this functionallity vulnerable for delete item
- Click on Delete item icon in cart and intercept the request change the Cart ID and from id parameter

- login into the victim user's account and observe the empty cart
