CVE-2024-0349

LOW

SourceCodester Engineers Online Portal 1.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to sensitive cookie without secure attribute. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-250117 was assigned to this vulnerability.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry
https://vuldb.com/?id.250117
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.250117

Scores

CVSS v3 3.7
EPSS 0.0039
EPSS Percentile 30.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-614
Status published
Products (1)
engineers_online_portal_project/engineers_online_portal 1.0
Published Jan 09, 2024
Tracked Since Feb 18, 2026