PT-2024-16032 · Sourcecodester · Sourcecodester Employee Management System

Joma Peralta

+1

·

Published

2024-01-29

·

Updated

2024-05-17

·

CVE-2024-1011

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Employee Management System version 1.0
Description A problematic issue was found in the Leave Handler component, specifically in the delete-leave.php file. The id argument is vulnerable to manipulation, leading to improper access controls. This issue can be exploited remotely.
Recommendations For SourceCodester Employee Management System version 1.0, consider restricting access to the delete-leave.php file until a fix is available. As a temporary workaround, avoid using the id argument in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-1011

Affected Products

Sourcecodester Employee Management System