A vulnerability was found in code-projects Dormitory Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file modifyuser.php. The manipulation of the argument mname leads to information disclosure. The exploit has been disclosed to the public and may be used. The identifier VDB-250577 was assigned to this vulnerability.
References
Link | Resource |
---|---|
https://github.com/yingqian1984/FirePunch/blob/main/7-Dormitory%20Management%20System%20has%20Database%20information%20leakage%20modifyuser.php.pdf | Broken Link |
https://vuldb.com/?ctiid.250577 | Permissions Required Third Party Advisory |
https://vuldb.com/?id.250577 | Permissions Required Third Party Advisory |
Configurations
History
24 Oct 2024, 16:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-532 |
19 Jan 2024, 14:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://vuldb.com/?id.250577 - Permissions Required, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.250577 - Permissions Required, Third Party Advisory | |
References | () https://github.com/yingqian1984/FirePunch/blob/main/7-Dormitory%20Management%20System%20has%20Database%20information%20leakage%20modifyuser.php.pdf - Broken Link | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
First Time |
Code-projects
Code-projects dormitory Management System |
|
CPE | cpe:2.3:a:code-projects:dormitory_management_system:1.0:*:*:*:*:*:*:* | |
CWE | NVD-CWE-noinfo |
12 Jan 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-12 22:15
Updated : 2024-10-24 16:35
NVD link : CVE-2024-0472
Mitre link : CVE-2024-0472
CVE.ORG link : CVE-2024-0472
JSON object : View
Products Affected
code-projects
- dormitory_management_system
CWE
NVD-CWE-noinfo
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-532Insertion of Sensitive Information into Log File