CVE-2024-39210

Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at index.php. This vulnerability allows attackers to read arbitrary PHP files and access other sensitive information within the application.
References
Link Resource
https://github.com/KRookieSec/CVE-2024-39210 Third Party Advisory
https://github.com/KRookieSec/CVE-2024-39210 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mayurik:best_house_rental_management_system:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:27

Type Values Removed Values Added
References () https://github.com/KRookieSec/CVE-2024-39210 - Third Party Advisory () https://github.com/KRookieSec/CVE-2024-39210 - Third Party Advisory

10 Oct 2024, 12:35

Type Values Removed Values Added
First Time Mayurik
Mayurik best House Rental Management System
CPE cpe:2.3:a:best_house_rental_management_system_project:best_house_rental_management_system:*:*:*:*:*:*:*:* cpe:2.3:a:mayurik:best_house_rental_management_system:*:*:*:*:*:*:*:*

09 Jul 2024, 16:22

Type Values Removed Values Added
CWE CWE-200

08 Jul 2024, 16:36

Type Values Removed Values Added
First Time Best House Rental Management System Project
Best House Rental Management System Project best House Rental Management System
References () https://github.com/KRookieSec/CVE-2024-39210 - () https://github.com/KRookieSec/CVE-2024-39210 - Third Party Advisory
CWE NVD-CWE-Other
Summary
  • (es) Se descubrió que Best House Rental Management System v1.0 contenía una vulnerabilidad de lectura de archivos arbitraria a través del parámetro Page en index.php. Esta vulnerabilidad permite a los atacantes leer archivos PHP arbitrarios y acceder a otra información confidencial dentro de la aplicación.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:best_house_rental_management_system_project:best_house_rental_management_system:*:*:*:*:*:*:*:*

05 Jul 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-05 16:15

Updated : 2024-11-21 09:27


NVD link : CVE-2024-39210

Mitre link : CVE-2024-39210

CVE.ORG link : CVE-2024-39210


JSON object : View

Products Affected

mayurik

  • best_house_rental_management_system
CWE
NVD-CWE-Other CWE-200

Exposure of Sensitive Information to an Unauthorized Actor