First published: Wed Dec 13 2023(Updated: )
A vulnerability classified as problematic has been found in PHPGurukul Teacher Subject Allocation Management System 1.0. Affected is an unknown function of the file /admin/course.php of the component Delete Course Handler. The manipulation of the argument delid leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247896.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Teacher Subject Allocation System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6766 is classified as problematic due to its potential impacts on user security.
To fix CVE-2023-6766, update the PHPGurukul Teacher Subject Allocation Management System to a patched version or implement input validation on the delid parameter.
CVE-2023-6766 is a cross-site request forgery (CSRF) vulnerability affecting the delete course functionality.
CVE-2023-6766 specifically affects the PHPGurukul Teacher Subject Allocation Management System version 1.0.
More details about CVE-2023-6766 can be found in the vulnerability reports and related documentation.