CVE-2024-6649: SourceCodester Employee and Visitor Gate Pass Logging System Users.php save_users cross-site request forgery
A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is the function saveusers of the file Users.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-271057 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6649?
CVE-2024-6649 is classified as a problematic vulnerability due to its potential for cross-site request forgery.
How do I fix CVE-2024-6649?
To fix CVE-2024-6649, implement CSRF tokens in the save_users function of the Users.php file.
Which software is affected by CVE-2024-6649?
CVE-2024-6649 affects SourceCodester Employee and Visitor Gate Pass Logging System version 1.0.
What type of vulnerability is CVE-2024-6649?
CVE-2024-6649 is a cross-site request forgery vulnerability that can lead to unauthorized actions on behalf of users.
What is the impact of CVE-2024-6649?
The impact of CVE-2024-6649 includes the potential for attackers to perform actions without user consent, compromising user accounts.