PT-2024-39422 · Sourcecodester · Sourcecodester Telecom Billing Management System

Shikang

·

Published

2024-09-22

·

Updated

2024-09-26

·

CVE-2024-9088

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Telecom Billing Management System version 1.0
Description A critical issue has been found in the login function, where the manipulation of the uname argument leads to a buffer overflow. The exploit has been disclosed to the public and may be used.
Recommendations For SourceCodester Telecom Billing Management System version 1.0, as a temporary workaround, consider disabling the login function until a patch is available. Restrict access to the login functionality to minimize the risk of exploitation. Avoid using the uname argument in the affected login function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-9088

Affected Products

Sourcecodester Telecom Billing Management System