PT-2024-15592 · Code Projects · Dormitory Management System

Firepunch

·

Published

2024-01-12

·

Updated

2024-05-17

·

CVE-2024-0475

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Dormitory Management System version 1.0
Description A critical issue has been found in the Dormitory Management System, affecting some unknown functionality of the file modifyuser.php. The manipulation of the user id argument leads to sql injection. The attack may be launched remotely.
Recommendations For version 1.0, consider disabling the modifyuser.php file or restricting access to it until a patch is available. Avoid using the user id argument in the affected functionality to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-0475

Affected Products

Dormitory Management System