PT-2024-17300 · Sourcecodester · Best House Rental Management System

Yasser Alshammari

+1

·

Published

2024-11-27

·

Updated

2024-12-04

·

CVE-2024-11860

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions SourceCodester Best House Rental Management System version 1.0
Description A critical vulnerability has been found in the system, affecting an unknown part of the file /rental/ajax.php?action=delete tenant of the component POST Request Handler. The manipulation of the id argument leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For version 1.0, consider disabling the delete tenant action in the /rental/ajax.php file until a patch is available. Restrict access to the /rental/ajax.php?action=delete tenant endpoint to minimize the risk of exploitation. Avoid using the id argument in the affected API endpoint until the issue is resolved.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-11860

Affected Products

Best House Rental Management System