An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and enables attackers to alter another user's information.
History

Thu, 26 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Dec 2024 22:15:00 +0000

Type Values Removed Values Added
Description An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and enables attackers to alter another user's information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-12-18T00:00:00

Updated: 2024-12-26T19:16:43.670Z

Reserved: 2024-12-06T00:00:00

Link: CVE-2024-55231

cve-icon Vulnrichment

Updated: 2024-12-26T19:16:28.862Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-12-18T22:15:07.127

Modified: 2024-12-26T20:15:22.363

Link: CVE-2024-55231

cve-icon Redhat

No data.