First published: Fri Aug 16 2024(Updated: )
A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /classes/Users.php?f=save of the component Add User Handler. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oretnom23 Yoga Class Registration System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7851 is classified as a critical vulnerability affecting the SourceCodester Yoga Class Registration System.
CVE-2024-7851 allows for improper authorization due to vulnerable code in the Add User Handler of the system.
To mitigate CVE-2024-7851, ensure that proper authorization checks are implemented in the affected file /classes/Users.php?f=save.
As of now, there is no official patch announced for CVE-2024-7851, so it's essential to review your application security practices.
CVE-2024-7851 specifically affects version 1.0 of the Yoga Class Registration System by Oretnom23.