CVE-2024-7367

Severity
6.9MEDIUM
EPSS
0.1%
top 69.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1

Description

A vulnerability, which was classified as problematic, was found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of the file /ajax.php?action=save_user. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273351.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

🔴Vulnerability Details

2
GHSA
GHSA-939p-28h4-46p5: A vulnerability, which was classified as problematic, was found in SourceCodester Simple Realtime Quiz System 12024-08-01
CVEList
SourceCodester Simple Realtime Quiz System ajax.php cross-site request forgery2024-08-01
CVE-2024-7367 (MEDIUM CVSS 6.9) | A vulnerability | cvebase.io