CVE-2024-3139

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function save_users of the file /classes/Users.php?f=save. The manipulation of the argument id leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-258914 is the identifier assigned to this vulnerability.
Configurations

No configuration.

History

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://github.com/Sospiro014/zday1/blob/main/Laboratory_Management_System.md - () https://github.com/Sospiro014/zday1/blob/main/Laboratory_Management_System.md -
References () https://vuldb.com/?ctiid.258914 - () https://vuldb.com/?ctiid.258914 -
References () https://vuldb.com/?id.258914 - () https://vuldb.com/?id.258914 -
References () https://vuldb.com/?submit.308207 - () https://vuldb.com/?submit.308207 -

02 Apr 2024, 12:50

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en SourceCodester Computer Laboratory Management System 1.0 y ha sido clasificada como crítica. La función save_users del archivo /classes/Users.php?f=save es afectada por esta vulnerabilidad. La manipulación del argumento id conduce a una autorización inadecuada. El ataque puede lanzarse de forma remota. El exploit ha sido divulgado al público y puede utilizarse. VDB-258914 es el identificador asignado a esta vulnerabilidad.

01 Apr 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-01 23:15

Updated : 2024-11-21 09:28


NVD link : CVE-2024-3139

Mitre link : CVE-2024-3139

CVE.ORG link : CVE-2024-3139


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization