CVE-2024-0264
high · 7.3A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /LoginRegistration.php. The manipulation of the argument formToken leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249820.
7.3
CVSS
18.2%
EPSS (exploit prob.)
97th
EPSS percentile
2024-01-07
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weaknesses
CWE-639
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| oretnom23 | clinic_queuing_system | 1.0 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/jmrcsnchz/ClinicQueueingSystem_RCE/
- https://github.com/jmrcsnchz/ClinicQueueingSystem_RCE/blob/main/clinicx.py
- https://vuldb.com/?ctiid.249820
- https://vuldb.com/?id.249820
- https://github.com/jmrcsnchz/ClinicQueueingSystem_RCE/
- https://github.com/jmrcsnchz/ClinicQueueingSystem_RCE/blob/main/clinicx.py
- https://vuldb.com/?ctiid.249820
- https://vuldb.com/?id.249820
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-0264