Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-34223. PoCs published by dovankha.
AI-analyzed exploit summary The repository describes an insecure permission vulnerability in SourceCodester Human Resource Management System 1.0, where attackers can manipulate leave request approvals via the /hrm/leaverequest.php endpoint using the 'msg' and 'id' parameters. The README provides a clear explanation of the vulnerability and its impact but lacks functional exploit code.
Description
Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.
Exploits (1)
The repository describes an insecure permission vulnerability in SourceCodester Human Resource Management System 1.0, where attackers can manipulate leave request approvals via the /hrm/leaverequest.php endpoint using the 'msg' and 'id' parameters. The README provides a clear explanation of the vulnerability and its impact but lacks functional exploit code.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N