PT-2024-39376 · Unknown · Sourcecodester Simple Forum-Discussion System

Shawroot

·

Published

2024-09-20

·

Updated

2024-09-24

·

CVE-2024-9032

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SourceCodester Simple Forum-Discussion System version 1.0
Description: A critical vulnerability was found in the SourceCodester Simple Forum-Discussion System. The issue affects an unknown function of the file /index.php. The manipulation of the page argument leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations: For SourceCodester Simple Forum-Discussion System version 1.0, as a temporary workaround, consider restricting access to the /index.php file until a patch is available. Avoid using the page argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-9032

Affected Products

Sourcecodester Simple Forum-Discussion System