CVE-2024-39210

Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at index.php. This vulnerability allows attackers to read arbitrary PHP files and access other sensitive information within the application.
References
Link Resource
https://github.com/KRookieSec/CVE-2024-39210 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mayurik:best_house_rental_management_system:*:*:*:*:*:*:*:*

History

10 Oct 2024, 12:35

Type Values Removed Values Added
CPE cpe:2.3:a:best_house_rental_management_system_project:best_house_rental_management_system:*:*:*:*:*:*:*:* cpe:2.3:a:mayurik:best_house_rental_management_system:*:*:*:*:*:*:*:*
First Time Mayurik best House Rental Management System
Mayurik

09 Jul 2024, 16:22

Type Values Removed Values Added
CWE CWE-200

08 Jul 2024, 16:36

Type Values Removed Values Added
CPE cpe:2.3:a:best_house_rental_management_system_project:best_house_rental_management_system:*:*:*:*:*:*:*:*
References () https://github.com/KRookieSec/CVE-2024-39210 - () https://github.com/KRookieSec/CVE-2024-39210 - Third Party Advisory
Summary
  • (es) Se descubrió que Best House Rental Management System v1.0 contenía una vulnerabilidad de lectura de archivos arbitraria a través del parámetro Page en index.php. Esta vulnerabilidad permite a los atacantes leer archivos PHP arbitrarios y acceder a otra información confidencial dentro de la aplicación.
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Best House Rental Management System Project
Best House Rental Management System Project best House Rental Management System

05 Jul 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-05 16:15

Updated : 2024-10-10 12:35


NVD link : CVE-2024-39210

Mitre link : CVE-2024-39210

CVE.ORG link : CVE-2024-39210


JSON object : View

Products Affected

mayurik

  • best_house_rental_management_system
CWE
NVD-CWE-Other CWE-200

Exposure of Sensitive Information to an Unauthorized Actor