CVE-2024-2576
HIGHOretnom23 Employee Task Management System - IDOR
Title source: ruleDescription
A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This affects an unknown part of the file /update-admin.php. The manipulation of the argument admin_id leads to authorization bypass. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257079.
Scores
CVSS v3
7.3
EPSS
0.0004
EPSS Percentile
11.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-639
Status
published
Affected Products (1)
oretnom23/employee_task_management_system
Timeline
Published
Mar 18, 2024
Tracked Since
Feb 18, 2026