CVE-2024-7645
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Aug 12, 2024
Updated: Aug 19, 2024
CWE ID 352
Summary
CVE-2024-7645 is a newly disclosed vulnerability affecting the User Page component of SourceCodester Clinics Patient Management System 1.0. The issue lies within the users.php file and involves a cross-site request forgery (CSRF) weakness. An attacker can exploit this flaw to initiate unauthorized actions on behalf of a victim, following a successful manipulation. Since the exploit has become public, there is a risk of widespread misuse.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.