An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information.
History

Thu, 26 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Dec 2024 22:15:00 +0000

Type Values Removed Values Added
Description An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-12-18T00:00:00

Updated: 2024-12-26T19:29:48.210Z

Reserved: 2024-12-06T00:00:00

Link: CVE-2024-55232

cve-icon Vulnrichment

Updated: 2024-12-26T19:29:39.191Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-12-18T22:15:07.297

Modified: 2024-12-26T20:15:22.673

Link: CVE-2024-55232

cve-icon Redhat

No data.