PT-2024-38596 · Unknown · Sourcecodester Online Graduate Tracer System
Wsstiger
+1
·
Published
2024-08-15
·
Updated
2024-08-19
·
CVE-2024-7809
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SourceCodester Online Graduate Tracer System version 1.0
Description
A vulnerability was found in the system, affecting an unknown functionality of the file /tracking/nbproject/. The manipulation leads to exposure of information through directory listing. The attack can be launched remotely.
Recommendations
For version 1.0, restrict directory access permissions to minimize the risk of exploitation and monitor for exploit attempts. Patch the system as soon as possible. Consider temporarily restricting access to the /tracking/nbproject/ directory until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Online Graduate Tracer System