PT-2024-24037 · Sourcecodester · Sourcecodester Computer Laboratory Management System
Sospiro
·
Published
2024-04-01
·
Updated
2024-06-04
·
CVE-2024-3139
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester Computer Laboratory Management System version 1.0
Description
A critical issue has been found in the function
save users of the file /classes/Users.php?f=save, where the manipulation of the argument id leads to improper authorization. The attack can be launched remotely.Recommendations
For SourceCodester Computer Laboratory Management System version 1.0, consider disabling the
save users function until a patch is available to prevent improper authorization. Restrict access to the /classes/Users.php?f=save file to minimize the risk of exploitation. Avoid using the argument id in the affected function until the issue is resolved.Exploit
Fix
Improper Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sourcecodester Computer Laboratory Management System