PT-2024-38628 · Sourcecodester · Sourcecodester Yoga Class Registration System

Wsstiger

+1

·

Published

2024-08-15

·

Updated

2024-08-29

·

CVE-2024-7851

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Yoga Class Registration System version 1.0
Description A critical issue has been discovered, affecting the Add User Handler component, specifically the file /classes/Users.php?f=save. This issue leads to improper authorization and can be exploited remotely. The exploit has been publicly disclosed.
Recommendations For SourceCodester Yoga Class Registration System version 1.0, consider restricting access to the /classes/Users.php?f=save file until a patch is available. As a temporary workaround, review and limit the use of the Add User Handler component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-7851

Affected Products

Sourcecodester Yoga Class Registration System