CVE-2024-55231

An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and enables attackers to alter another user's information.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:online_notes_sharing_management_system:1.0:*:*:*:*:*:*:*

History

27 Mar 2025, 16:30

Type Values Removed Values Added
References () https://github.com/CV1523/CVEs/blob/main/CVE-2024-55231.md - () https://github.com/CV1523/CVEs/blob/main/CVE-2024-55231.md - Exploit, Third Party Advisory
CPE cpe:2.3:a:phpgurukul:online_notes_sharing_management_system:1.0:*:*:*:*:*:*:*
First Time Phpgurukul
Phpgurukul online Notes Sharing Management System

26 Dec 2024, 20:15

Type Values Removed Values Added
References () https://github.com/CV1523/CVEs/blob/main/CVE-2024-55231.md - () https://github.com/CV1523/CVEs/blob/main/CVE-2024-55231.md -
CWE CWE-639
Summary
  • (es) Una vulnerabilidad de IDOR en edit-notes.php module de PHPGurukul Online Notes Sharing Management System v1.0 permite que usuarios no autorizados modifiquen notas pertenecientes a otras cuentas debido a la falta de comprobaciones de autorización. Esta falla expone datos confidenciales y permite a los atacantes alterar la información de otro usuario.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

18 Dec 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-18 22:15

Updated : 2025-03-27 16:30


NVD link : CVE-2024-55231

Mitre link : CVE-2024-55231

CVE.ORG link : CVE-2024-55231


JSON object : View

Products Affected

phpgurukul

  • online_notes_sharing_management_system
CWE
CWE-639

Authorization Bypass Through User-Controlled Key