SourceCodester Online Graduate Tracer System Vulnerability: Information Disclosure Risk
CVE-2024-7842

7.5HIGH

Key Information:

Vendor
CVE Published:
15 August 2024

Summary

A notable vulnerability within the SourceCodester Online Graduate Tracer System version 1.0 has been identified, specifically affecting the /tracking/admin/export_it.php file. This issue arises due to improper processing, which can lead to unauthorized information disclosure. Malicious actors may exploit this vulnerability remotely, posing a threat to the integrity and confidentiality of data handled by the system. Public disclosure of the exploit has occurred, signaling the urgency for users to assess their security measures.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD Database
.