Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-55058

Опубликовано: 17 дек. 2024
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phpgurukul:online_birth_certificate_system:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 23%
0.00078
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-706

Связанные уязвимости

CVSS3: 4.3
github
около 1 года назад

An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.

EPSS

Процентиль: 23%
0.00078
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-706