Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. tastyigniter/tastyigniter
  4. ›
  5. CVE-2024-44314

CVE-2024-44314: TastyIgniter Has an Incorrect Access Control Vulnerability

March 18, 2025 (updated March 21, 2025)

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order’s status. This flaw can be exploited remotely, leading to unauthorized order manipulation.

References

  • github.com/advisories/GHSA-w5h7-mw56-4v7x
  • github.com/tastyigniter/TastyIgniter
  • github.com/tastyigniter/TastyIgniter/blob/3.x/app/admin/controllers/Orders.php
  • medium.com/@cnetsec/cve-2024-44314-incorrect-access-control-in-function-updateorder-fc5f2b1b0467
  • nvd.nist.gov/vuln/detail/CVE-2024-44314

Code Behaviors & Features

Detect and mitigate CVE-2024-44314 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 4.0.0

Fixed versions

  • 4.0.0

Solution

Upgrade to version 4.0.0 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-285: Improper Authorization

Source file

packagist/tastyigniter/tastyigniter/CVE-2024-44314.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 00:15:17 +0000.