CVE-2024-9083 – SourceCodester Employee Management System add-admin.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-9083
A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file /Admin/add-admin.php. The manipulation of the argument txtfullname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/zz0zz0/CVE/blob/main/Employee%20Management%20System%20--XSS/Employee%20Management%20System%20--XSS.md https://vuldb.com/?ctiid.278253 https://vuldb.com/?id.278253 https://vuldb.com/?submit.411568 https://www.sourcecodester.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-2577 – SourceCodester Employee Task Management System update-employee.php authorization
https://notcve.org/view.php?id=CVE-2024-2577
A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /update-employee.php. The manipulation of the argument admin_id leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20Employee%20Task%20Management%20System/IDOR%20-%20update-employee.php.md https://vuldb.com/?ctiid.257080 https://vuldb.com/?id.257080 • CWE-639: Authorization Bypass Through User-Controlled Key •
CVE-2024-2576 – SourceCodester Employee Task Management System update-admin.php authorization
https://notcve.org/view.php?id=CVE-2024-2576
A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This affects an unknown part of the file /update-admin.php. The manipulation of the argument admin_id leads to authorization bypass. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20Employee%20Task%20Management%20System/IDOR%20-%20update-admin.php.md https://vuldb.com/?ctiid.257079 https://vuldb.com/?id.257079 • CWE-639: Authorization Bypass Through User-Controlled Key •
CVE-2024-2575 – SourceCodester Employee Task Management System task-details.php authorization
https://notcve.org/view.php?id=CVE-2024-2575
A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0. Affected by this issue is some unknown functionality of the file /task-details.php. The manipulation of the argument task_id leads to authorization bypass. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20Employee%20Task%20Management%20System/IDOR%20-%20task-details.php.md https://vuldb.com/?ctiid.257078 https://vuldb.com/?id.257078 • CWE-639: Authorization Bypass Through User-Controlled Key •
CVE-2024-2574 – SourceCodester Employee Task Management System edit-task.php authorization
https://notcve.org/view.php?id=CVE-2024-2574
A vulnerability classified as critical was found in SourceCodester Employee Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit-task.php. The manipulation of the argument task_id leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20Employee%20Task%20Management%20System/IDOR%20-%20edit-task.php.md https://vuldb.com/?ctiid.257077 https://vuldb.com/?id.257077 • CWE-639: Authorization Bypass Through User-Controlled Key •