PT-2024-36466 · Unknown · Phpgurukul Online Birth Certificate System

Mohammed Athif

·

Published

2024-12-17

·

Updated

2025-03-27

·

CVE-2024-55058

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul Online Birth Certificate System version 1.0
Description An insecure direct object reference (IDOR) vulnerability was discovered in the PHPGurukul Online Birth Certificate System. This issue resides in the viewid parameter of "/user/view-application-detail.php". Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.
Recommendations To resolve this issue, update PHPGurukul Online Birth Certificate System to a version that includes a fix for this vulnerability. As a temporary workaround, consider restricting access to the "/user/view-application-detail.php" endpoint to minimize the risk of exploitation. Avoid using the viewid parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-55058

Affected Products

Phpgurukul Online Birth Certificate System