CVE-2024-55232

MEDIUM

Phpgurukul Online Notes Sharing Manag... - Authentication Bypass by Spoofing

Title source: rule
STIX 2.1

Description

An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information.

Scores

CVSS v3 5.4
EPSS 0.0006
EPSS Percentile 18.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (1)
phpgurukul/online_notes_sharing_management_system 1.0
Published Dec 18, 2024
Tracked Since Feb 18, 2026