CVE-2024-10158: PHPGurukul Boat Booking System session_start session fixiation
Published Oct 19, 2024
·Updated
A vulnerability classified as problematic has been found in PHPGurukul Boat Booking System 1.0. Affected is the function sessionstart. The manipulation leads to session fixiation. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Phpgurukul Boat Booking System=1.0
Event History
Oct 19, 2024
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10158?
CVE-2024-10158 is classified as a problematic vulnerability.
2
How do I fix CVE-2024-10158?
To fix CVE-2024-10158, it is recommended to implement session regeneration techniques after user authentication.
3
What type of vulnerability is CVE-2024-10158?
CVE-2024-10158 is a session fixation vulnerability that allows attackers to hijack user sessions.
4
Is CVE-2024-10158 remotely exploitable?
Yes, CVE-2024-10158 can be exploited remotely.
5
Which version of PHPGurukul Boat Booking System is affected by CVE-2024-10158?
CVE-2024-10158 affects version 1.0 of PHPGurukul Boat Booking System.