SourceCodester Employee Management System Leave delete-leave.php access control
Published Jan 29, 2024
8.8
HIGHCVSS 3.1
EPSS 0.64%
Description
A vulnerability classified as problematic was found in SourceCodester Employee Management System 1.0. This vulnerability affects unknown code of the file delete-leave.php of the component Leave Handler. The manipulation of the argument id leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252280.
Affected products
-
Affected
- 1.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| SourceCodester | Employee Management System | unknown | Affected
|
- 1.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-16788 Advisory
- https://github.com/jomskiller/Employee-Managemet-System---Broken-Access-Control exploitThird Party Advisory
- https://vuldb.com/?ctiid.252280 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.252280 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-16788 | Advisory | |
| https://github.com/jomskiller/Employee-Managemet-System---Broken-Access-Control | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.252280 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.252280 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data