An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and enables attackers to alter another user's information.
History

Thu, 27 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Phpgurukul
Phpgurukul online Notes Sharing Management System
CPEs cpe:2.3:a:phpgurukul:online_notes_sharing_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Phpgurukul
Phpgurukul online Notes Sharing Management System

Thu, 26 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Dec 2024 22:15:00 +0000

Type Values Removed Values Added
Description An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and enables attackers to alter another user's information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-12-26T19:16:43.670Z

Reserved: 2024-12-06T00:00:00

Link: CVE-2024-55231

cve-icon Vulnrichment

Updated: 2024-12-26T19:16:28.862Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-18T22:15:07.127

Modified: 2025-03-27T16:30:14.617

Link: CVE-2024-55231

cve-icon Redhat

No data.