CVE-2024-1823

A vulnerability classified as critical was found in CodeAstro Simple Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file users.php of the component Backend. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254611.
Configurations

Configuration 1 (hide)

cpe:2.3:a:codeastro:simple_voting_system:1.0:*:*:*:*:*:*:*

History

07 Dec 2024, 02:59

Type Values Removed Values Added
References () https://docs.qq.com/doc/DYll0ZEFKcUdGYlNr - () https://docs.qq.com/doc/DYll0ZEFKcUdGYlNr - Exploit
References () https://vuldb.com/?ctiid.254611 - () https://vuldb.com/?ctiid.254611 - Permissions Required
References () https://vuldb.com/?id.254611 - () https://vuldb.com/?id.254611 - Third Party Advisory
CWE NVD-CWE-noinfo
First Time Codeastro
Codeastro simple Voting System
CPE cpe:2.3:a:codeastro:simple_voting_system:1.0:*:*:*:*:*:*:*

21 Nov 2024, 08:51

Type Values Removed Values Added
References () https://docs.qq.com/doc/DYll0ZEFKcUdGYlNr - () https://docs.qq.com/doc/DYll0ZEFKcUdGYlNr -
References () https://vuldb.com/?ctiid.254611 - () https://vuldb.com/?ctiid.254611 -
References () https://vuldb.com/?id.254611 - () https://vuldb.com/?id.254611 -

29 Feb 2024, 01:43

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue encontrada en CodeAstro Simple Voting System 1.0 y clasificada como crítica. Una función desconocida del archivo users.php del componente Backend es afectada por esta vulnerabilidad. La manipulación conduce a controles de acceso inadecuados. El ataque se puede lanzar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. El identificador asociado de esta vulnerabilidad es VDB-254611.

23 Feb 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-23 16:15

Updated : 2024-12-07 02:59


NVD link : CVE-2024-1823

Mitre link : CVE-2024-1823

CVE.ORG link : CVE-2024-1823


JSON object : View

Products Affected

codeastro

  • simple_voting_system
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo