CVE-2024-12186

MEDIUM

code-projects Hotel Management System 1.0 - Stack-Based Buffer Overflow in Available Room Handler

Title source: llm
STIX 2.1

Description

A vulnerability was found in code-projects Hotel Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file hotelnew.c of the component Available Room Handler. The manipulation of the argument admin_entry leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

References (5)

Core 5
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.286907
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.286907
Third Party Advisory third-party-advisory
https://vuldb.com/?submit.454846
Exploit, Third Party Advisory exploit
https://github.com/1zzan/cve/blob/main/STACK-OVERFLOW2.md
Product product
https://code-projects.org/

Scores

CVSS v3 5.3
EPSS 0.0009
EPSS Percentile 25.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-121 CWE-787
Status published
Products (1)
code-projects/hotel_management_system 1.0
Published Dec 05, 2024
Tracked Since Feb 18, 2026