CVE-2024-55231

MEDIUM

Phpgurukul Online Notes Sharing Management System - IDOR

Title source: rule
STIX 2.1

Description

An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and enables attackers to alter another user's information.

References (1)

Core 1

Scores

CVSS v3 4.3
EPSS 0.0008
EPSS Percentile 23.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
phpgurukul/online_notes_sharing_management_system 1.0
Published Dec 18, 2024
Tracked Since Feb 18, 2026