CVE-2024-2569
published 2024-03-18CVE-2024-2569: A vulnerability was found in SourceCodester Employee Task Management System 1.0 and classified as critical. Affected by this issue is some unknown…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.18%
64.2th percentile
A vulnerability was found in SourceCodester Employee Task Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin-manage-user.php. The manipulation leads to execution after redirect. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257072.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oretnom23 | employee_task_management_system | — | — |
| sourcecodester | employee_task_management_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8mqv-cx74-94cc: A vulnerability was found in SourceCodester Employee Task Management System 1
ghsa_unreviewed·2024-03-18
CVE-2024-2569 [HIGH] CWE-698 GHSA-8mqv-cx74-94cc: A vulnerability was found in SourceCodester Employee Task Management System 1
A vulnerability was found in SourceCodester Employee Task Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin-manage-user.php. The manipulation leads to execution after redirect. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257072.
Red Hat
kernel: pstore: inode: Only d_invalidate() is needed
vendor_redhat·2024-05-01·CVSS 5.5
CVE-2024-27389 [MEDIUM] kernel: pstore: inode: Only d_invalidate() is needed
kernel: pstore: inode: Only d_invalidate() is needed
In the Linux kernel, the following vulnerability has been resolved:
pstore: inode: Only d_invalidate() is needed
Unloading a modular pstore backend with records in pstorefs would
trigger the dput() double-drop warning:
WARNING: CPU: 0 PID: 2569 at fs/dcache.c:762 dput.part.0+0x3f3/0x410
Using the combo of d_drop()/dput() (as mentioned in
Documentation/filesystems/vfs.rst) isn't the right approach here, and
leads to the reference counting problem seen above. Use d_invalidate()
and update the code to not bother checking for error codes that can
never happen.
---
In the Linux kernel, the following vulnerability has been resolved:
pstore: inode: Only d_invalidate() is needed
The Linux kernel CVE team has assigned CVE-2024-27389 to this iss
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20Employee%20Task%20Management%20System/Execution%20After%20Redirect%20-%20admin-manage-user.php.mdhttps://vuldb.com/?ctiid.257072https://vuldb.com/?id.257072https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20Employee%20Task%20Management%20System/Execution%20After%20Redirect%20-%20admin-manage-user.php.mdhttps://vuldb.com/?ctiid.257072https://vuldb.com/?id.257072
2024-03-18
Published