CVE-2024-5363
published 2024-05-26CVE-2024-5363: A vulnerability classified as critical was found in SourceCodester Best House Rental Management System up to 1.0. Affected by this vulnerability is an unknown…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.47%
37.8th percentile
A vulnerability classified as critical was found in SourceCodester Best House Rental Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266275.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mayurik | best_house_rental_management_system | — | — |
| sourcecodester | best_house_rental_management_system | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_oracle7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Observability Services Overlay (nginx) — CVE-2023-5363
vendor_oracle·2024-04-15·CVSS 7.5
CVE-2023-5363 [HIGH] Oracle Oracle Communications Risk Matrix: Observability Services Overlay (nginx) — CVE-2023-5363
Oracle Oracle Communications Risk Matrix: Observability Services Overlay (nginx) vulnerability
CVE: CVE-2023-5363
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle MySQL Risk Matrix: Connector/C++ (OpenSSL) — CVE-2023-5363
vendor_oracle·2024-01-15·CVSS 7.5
CVE-2023-5363 [HIGH] Oracle Oracle MySQL Risk Matrix: Connector/C++ (OpenSSL) — CVE-2023-5363
Oracle Oracle MySQL Risk Matrix: Connector/C++ (OpenSSL) vulnerability
CVE: CVE-2023-5363
CVSS: 7.5
Protocol: MySQL Protocol
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-35911 kernel: ice: fix memory corruption bug with suspend and rebuild
bugzilla·2024-05-20·CVSS 7.8
CVE-2024-35911 [HIGH] CVE-2024-35911 kernel: ice: fix memory corruption bug with suspend and rebuild
CVE-2024-35911 kernel: ice: fix memory corruption bug with suspend and rebuild
In the Linux kernel, the following vulnerability has been resolved:
ice: fix memory corruption bug with suspend and rebuild
The Linux kernel CVE team has assigned CVE-2024-35911 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024051956-CVE-2024-35911-f6f9@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2281640]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:5363 https://access.redhat.com/errata/RHSA-2024:5363
Bugzilla
CVE-2024-27049 kernel: wifi: mt76: mt7925e: fix use-after-free in free_irq()
bugzilla·2024-05-01·CVSS 7.8
CVE-2024-27049 [HIGH] CVE-2024-27049 kernel: wifi: mt76: mt7925e: fix use-after-free in free_irq()
CVE-2024-27049 kernel: wifi: mt76: mt7925e: fix use-after-free in free_irq()
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7925e: fix use-after-free in free_irq()
The Linux kernel CVE team has assigned CVE-2024-27049 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050114-CVE-2024-27049-a5a1@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278430]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:5363 https://access.redhat.com/errata/RHSA-2024:5363
https://github.com/rockersiyuan/CVE/blob/main/SourceCodester_House_Rental_Management_System_Sql_Inject-1.mdhttps://vuldb.com/?ctiid.266275https://vuldb.com/?id.266275https://vuldb.com/?submit.343427https://github.com/rockersiyuan/CVE/blob/main/SourceCodester_House_Rental_Management_System_Sql_Inject-1.mdhttps://vuldb.com/?ctiid.266275https://vuldb.com/?id.266275https://vuldb.com/?submit.343427
2024-05-26
Published