CVE-2024-55232

An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information.
References
Link Resource
https://github.com/CV1523/CVEs/blob/main/CVE-2024-55232.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:online_notes_sharing_management_system:1.0:*:*:*:*:*:*:*

History

28 Mar 2025, 16:21

Type Values Removed Values Added
References () https://github.com/CV1523/CVEs/blob/main/CVE-2024-55232.md - () https://github.com/CV1523/CVEs/blob/main/CVE-2024-55232.md - Exploit, Third Party Advisory
CPE cpe:2.3:a:phpgurukul:online_notes_sharing_management_system:1.0:*:*:*:*:*:*:*
First Time Phpgurukul
Phpgurukul online Notes Sharing Management System

26 Dec 2024, 20:15

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de IDOR en manage-notes.php module en PHPGurukul Online Notes Sharing Management System v1.0 permite que usuarios no autorizados eliminen notas pertenecientes a otras cuentas debido a la falta de comprobaciones de autorización. Esta falla permite a los atacantes eliminar la información de otro usuario.
CWE CWE-290
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

18 Dec 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-18 22:15

Updated : 2025-03-28 16:21


NVD link : CVE-2024-55232

Mitre link : CVE-2024-55232

CVE.ORG link : CVE-2024-55232


JSON object : View

Products Affected

phpgurukul

  • online_notes_sharing_management_system
CWE
CWE-290

Authentication Bypass by Spoofing