An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.
History

Thu, 27 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Phpgurukul
Phpgurukul online Birth Certificate System
CPEs cpe:2.3:a:phpgurukul:online_birth_certificate_system:1.0:*:*:*:*:*:*:*
Vendors & Products Phpgurukul
Phpgurukul online Birth Certificate System

Wed, 18 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-706
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Dec 2024 20:45:00 +0000

Type Values Removed Values Added
Description An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-12-18T15:31:10.430Z

Reserved: 2024-12-06T00:00:00

Link: CVE-2024-55058

cve-icon Vulnrichment

Updated: 2024-12-18T15:29:30.605Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-17T21:15:08.510

Modified: 2025-03-27T16:23:45.773

Link: CVE-2024-55058

cve-icon Redhat

No data.