First published: Fri Aug 09 2024(Updated: )
Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oretnom23 Computer Laboratory Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41332 is classified as a medium severity vulnerability due to its potential impact on data integrity.
To fix CVE-2024-41332, apply access control restrictions in the delete_category function to ensure only authorized users can delete categories.
CVE-2024-41332 affects users of Sourcecodester Computer Laboratory Management System version 1.0.
CVE-2024-41332 is an access control vulnerability that allows authenticated attackers to delete categories improperly.
CVE-2024-41332 can be exploited by authenticated attackers with low-level privileges, making it relatively easy to execute.