PT-2024-15589 · Unknown · Code-Projects Dormitory Management System

Firepunch

·

Published

2024-01-12

·

Updated

2024-10-24

·

CVE-2024-0472

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions code-projects Dormitory Management System version 1.0
Description A vulnerability was found in the code-projects Dormitory Management System, affecting some unknown processing of the file modifyuser.php. The manipulation of the argument mname leads to information disclosure. The exploit has been disclosed to the public and may be used.
Recommendations For code-projects Dormitory Management System version 1.0, consider restricting access to the modifyuser.php file until a patch is available. As a temporary workaround, avoid using the mname argument in the affected file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2024-0472

Affected Products

Code-Projects Dormitory Management System