CVE-2024-24496
CRITICALDaily Habit Tracker 1.0 - Unauthenticated Tracker Manipulation via Home and Tracker Management Endpoints
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-24496. PoCs published by Yevhenii Butenko.
AI-analyzed exploit summary This exploit demonstrates broken access control in Daily Habit Tracker 1.0, allowing unauthenticated users to access, create, update, and delete trackers via direct HTTP requests. The PoC includes specific endpoints and payloads for each action.
Description
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.
Exploits (1)
This exploit demonstrates broken access control in Daily Habit Tracker 1.0, allowing unauthenticated users to access, create, update, and delete trackers via direct HTTP requests. The PoC includes specific endpoints and payloads for each action.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H