7.5
CVE-2024-42774
- EPSS 0.23%
- Veröffentlicht 22.08.2024 17:15:06
- Zuletzt bearbeitet 30.04.2025 16:50:53
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jayesh ≫ Hotel Management System Version1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.455 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.