PT-2024-29360 · Sourcecodester · Sourcecodester Computer Laboratory Management System

Published

2024-08-09

·

Updated

2024-08-21

·

CVE-2024-41332

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Sourcecodester Computer Laboratory Management System version 1.0
Description The issue is related to incorrect access control in the delete category function, allowing authenticated attackers with low-level privileges to arbitrarily delete categories. This can lead to unauthorized system access.
Recommendations For Sourcecodester Computer Laboratory Management System version 1.0, consider disabling the delete category function until a patch is available to prevent unauthorized category deletion. Restrict access to the delete category function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-41332

Affected Products

Sourcecodester Computer Laboratory Management System