PT-2023-32767 · Unknown · Phpgurukul Teacher Subject Allocation Management System

Dhabaleshwar

·

Published

2023-12-13

·

Updated

2024-05-17

·

CVE-2023-6766

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul Teacher Subject Allocation Management System version 1.0
Description A problematic vulnerability has been found in the PHPGurukul Teacher Subject Allocation Management System. The issue affects an unknown function of the file /admin/course.php, specifically the component Delete Course Handler. The manipulation of the delid argument leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For PHPGurukul Teacher Subject Allocation Management System version 1.0, consider disabling the Delete Course Handler component or restricting access to the /admin/course.php file until a patch is available. As a temporary workaround, avoid using the delid argument in the affected API endpoint. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-6766

Affected Products

Phpgurukul Teacher Subject Allocation Management System