VulnerabilityModified
CVE-2024-6014
A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0.
MEDIUM 5.3EPSS 0.50%
Does this matter?
Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unknown function of the file edithis.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-268722 is the identifier assigned to this vulnerability.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.50% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- itsourcecode/document management system project in php with source code
- Source
- cna@vuldb.com
References
- https://github.com/gabriel202212/cve/issues/2Exploit, Technical Description, Third Party Advisory
- https://vuldb.com/?ctiid.268722Permissions Required
- https://vuldb.com/?id.268722Third Party Advisory
- https://vuldb.com/?submit.357246Issue Tracking
- https://github.com/gabriel202212/cve/issues/2Exploit, Technical Description, Third Party Advisory
- https://vuldb.com/?ctiid.268722Permissions Required
- https://vuldb.com/?id.268722Third Party Advisory
- https://vuldb.com/?submit.357246Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.