CVE-2024-5365
published 2024-05-26CVE-2024-5365: A vulnerability, which was classified as critical, was found in SourceCodester Best House Rental Management System up to 1.0. This affects an unknown part of…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.49%
38.9th percentile
A vulnerability, which was classified as critical, was found in SourceCodester Best House Rental Management System up to 1.0. This affects an unknown part of the file manage_payment.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266277 was assigned to this vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mayurik | best_house_rental_management_system | — | — |
| sourcecodester | best_house_rental_management_system | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-52771 kernel: cxl/port: Fix delete_endpoint() vs parent unregistration race
bugzilla·2024-05-22·CVSS 4.7
CVE-2023-52771 [MEDIUM] CVE-2023-52771 kernel: cxl/port: Fix delete_endpoint() vs parent unregistration race
CVE-2023-52771 kernel: cxl/port: Fix delete_endpoint() vs parent unregistration race
In the Linux kernel, the following vulnerability has been resolved:
cxl/port: Fix delete_endpoint() vs parent unregistration race
The Linux kernel CVE team has assigned CVE-2023-52771 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024052150-CVE-2023-52771-43ad@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:5365 https://access.redhat.com/errata/RHSA-2024:5365
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:5364 https://access.redhat.com/errata/RHSA-2024:5364
---
This issue has been addres
Bugzilla
CVE-2023-52651 kernel: wifi: ath10k: fix NULL pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev()
bugzilla·2024-05-01
CVE-2023-52651 [MEDIUM] CVE-2023-52651 kernel: wifi: ath10k: fix NULL pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev()
CVE-2023-52651 kernel: wifi: ath10k: fix NULL pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev()
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath10k: fix NULL pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev()
The Linux kernel CVE team has assigned CVE-2023-52651 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050110-CVE-2023-52651-5907@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278520]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:5365 https://access.redhat.com/errata/RHSA-2024:5365
---
This issue has been addressed in the following products:
Red Hat Enterpr
Bugzilla
CVE-2024-27046 kernel: nfp: flower: handle acti_netdevs allocation failure
bugzilla·2024-05-01·CVSS 5.5
CVE-2024-27046 [MEDIUM] CVE-2024-27046 kernel: nfp: flower: handle acti_netdevs allocation failure
CVE-2024-27046 kernel: nfp: flower: handle acti_netdevs allocation failure
In the Linux kernel, the following vulnerability has been resolved:
nfp: flower: handle acti_netdevs allocation failure
The Linux kernel CVE team has assigned CVE-2024-27046 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050113-CVE-2024-27046-4694@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278436]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:4928 https://access.redhat.com/errata/RHSA-2024:4928
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:5365 https://access.redhat.com/errata/RHSA-20
https://github.com/rockersiyuan/CVE/blob/main/SourceCodester_House_Rental_Management_System_Sql_Inject-3.mdhttps://vuldb.com/?ctiid.266277https://vuldb.com/?id.266277https://vuldb.com/?submit.343432https://github.com/rockersiyuan/CVE/blob/main/SourceCodester_House_Rental_Management_System_Sql_Inject-3.mdhttps://vuldb.com/?ctiid.266277https://vuldb.com/?id.266277https://vuldb.com/?submit.343432
2024-05-26
Published