CVE-2024-24496

CRITICAL

Daily Habit Tracker 1.0 - Unauthenticated Tracker Manipulation via Home and Tracker Management Endpoints

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-24496. PoCs published by Yevhenii Butenko.

AI-analyzed exploit summary This exploit demonstrates broken access control in Daily Habit Tracker 1.0, allowing unauthenticated users to access, create, update, and delete trackers via direct HTTP requests. The PoC includes specific endpoints and payloads for each action.

Description

An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.

Exploits (1)

exploitdb WORKING POC
by Yevhenii Butenko · webappsphp
https://www.exploit-db.com/exploits/51954

This exploit demonstrates broken access control in Daily Habit Tracker 1.0, allowing unauthenticated users to access, create, update, and delete trackers via direct HTTP requests. The PoC includes specific endpoints and payloads for each action.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Daily Habit Tracker 1.0
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.1950
EPSS Percentile 97.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-284 CWE-287
Status published
Products (1)
remyandrade/daily_habit_tracker 1.0
Published Feb 08, 2024
Tracked Since Feb 18, 2026