First published: Tue May 14 2024(Updated: )
Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Human Resource Management System | ||
Sourcecodester Human Resource Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34223 is classified as a critical vulnerability due to its potential impact on the approval process for leave requests.
To mitigate CVE-2024-34223, update to the latest version of the SourceCodester Human Resource Management System that addresses this permission issue.
CVE-2024-34223 can be exploited by attackers to unauthorizedly approve or reject leave requests, leading to potential misuse of the HR management system.
Any organization using SourceCodester Human Resource Management System version 1.0 is vulnerable to CVE-2024-34223.
While the best course of action is to update the software, temporarily restricting access to the leave request functionality can serve as a workaround for CVE-2024-34223.