CVE-2024-55232
Last modified
CVE-2024-55232 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Online Notes Sharing Management System | 1.0 |
References
- https://github.com/CV1523/CVEs/blob/main/CVE-2024-55232.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-55232?
How severe is CVE-2024-55232?
How do I fix CVE-2024-55232?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-55225An issue in the component src/api/identity.rs of Vaultwarden…9.8
- CVE-2024-55226Vaultwarden v1.32.5 was discovered to contain an authenticat…5.4
- CVE-2024-55227A cross-site scripting (XSS) vulnerability in the Events/Age…9
- CVE-2024-55228A cross-site scripting (XSS) vulnerability in the Product mo…9
- CVE-2024-5523SQL injection vulnerability in Astrotalks affecting version …8.8
- CVE-2024-55231An IDOR vulnerability in the edit-notes.php module of PHPGur…4.3
- CVE-2024-55238OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An atta…8.8
- CVE-2024-55239A reflected Cross-Site Scripting vulnerability in the standa…5.4
- CVE-2024-5524Information exposure vulnerability in Astrotalks affecting v…5.3
- CVE-2024-55241An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 …8.8
- CVE-2024-5525Improper privilege management vulnerability in Astrotalks af…8.8
- CVE-2024-5526Grafana OnCall is an easy-to-use on-call management tool tha…9.1
Are you affected by CVE-2024-55232?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
