mega.nzexploit
https://mega.nz/file/TU1X3TIQ CVE-2024-0349
LOW
SourceCodester Engineers Online Portal missing secure attribute
Record summary
CVE-2024-0349 has a selected CVSS score of 3.7 (low).
Description
A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to sensitive cookie without secure attribute. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-250117 was assigned to this vulnerability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 11, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Engineers Online PortalBrowse SourceCodester / Engineers Online Portal | CVE List | 1.0 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-0349 vuldb.comsignaturepermissions required
https://vuldb.com/?ctiid.250117 vuldb.comvdb entry
https://vuldb.com/?id.250117