CVE-2024-0264: SourceCodester Clinic Queuing System LoginRegistration.php authorization
A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /LoginRegistration.php. The manipulation of the argument formToken leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249820.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0264?
CVE-2024-0264 has been declared as a critical vulnerability.
How does CVE-2024-0264 work?
CVE-2024-0264 allows an attacker to bypass authorization through manipulation of the formToken argument in the /LoginRegistration.php file.
Which versions of the Clinic Queuing System are affected by CVE-2024-0264?
CVE-2024-0264 affects version 1.0 of the Oretnom23 Clinic Queuing System.
How do I fix CVE-2024-0264?
To fix CVE-2024-0264, ensure you validate and secure the formToken against unauthorized manipulation.
Can CVE-2024-0264 affect my data security?
Yes, CVE-2024-0264 can lead to unauthorized access, compromising the security of user data.