CVE-2024-54818

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 8, 2025
CWE ID 281

Summary

CVE-2024-54818 is a newly identified vulnerability affecting the SourceCodester Computer Laboratory Management System version 1.0. The issue involves Incorrect Access Control, which allows unauthorized users to access sensitive information through the /php-lms/admin/?page=user/list endpoint. This vulnerability poses a significant risk, as it can lead to data theft or system compromise. Unauthenticated attackers can potentially exploit this issue to gain administrative access and manipulate user accounts, putting the entire system at risk. Upgrading to a patched version or implementing access control best practices are recommended mitigations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share