SourceCodester Online Graduate Tracer System Vulnerability: Information Disclosure Risk
CVE-2024-7842
7.5HIGH
Summary
A notable vulnerability within the SourceCodester Online Graduate Tracer System version 1.0 has been identified, specifically affecting the /tracking/admin/export_it.php file. This issue arises due to improper processing, which can lead to unauthorized information disclosure. Malicious actors may exploit this vulnerability remotely, posing a threat to the integrity and confidentiality of data handled by the system. Public disclosure of the exploit has occurred, signaling the urgency for users to assess their security measures.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD Database