CVE-2024-2577: SourceCodester Employee Task Management System update-employee.php authorization
A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /update-employee.php. The manipulation of the argument adminid leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257080.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2577?
CVE-2024-2577 is classified as a critical vulnerability.
How does CVE-2024-2577 affect the Employee Task Management System?
CVE-2024-2577 affects the authorization process due to manipulation of the admin_id argument in the /update-employee.php file.
What types of exploits can be performed using CVE-2024-2577?
Exploiting CVE-2024-2577 can lead to unauthorized access or privilege escalation in the Employee Task Management System.
How do I fix CVE-2024-2577?
To fix CVE-2024-2577, ensure proper validation of user inputs and restrict access controls in the affected scripts.
What versions of the Employee Task Management System are affected by CVE-2024-2577?
CVE-2024-2577 affects version 1.0 of the SourceCodester Employee Task Management System.