A vulnerability classified as critical has been found in SourceCodester Payroll Management System 1.0. This affects the function login of the file main. The manipulation leads to buffer overflow. The exploit has been disclosed to the public and may be used.
History

Wed, 30 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Razormist
Razormist payroll Management System
CPEs cpe:2.3:a:razormist:payroll_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Razormist
Razormist payroll Management System

Fri, 25 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester payroll Management System
CPEs cpe:2.3:a:sourcecodester:payroll_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester payroll Management System
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Oct 2024 01:45:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as critical has been found in SourceCodester Payroll Management System 1.0. This affects the function login of the file main. The manipulation leads to buffer overflow. The exploit has been disclosed to the public and may be used.
Title SourceCodester Payroll Management System main login buffer overflow
Weaknesses CWE-120
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:A/AC:L/Au:N/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-10-25T01:31:06.510Z

Updated: 2024-10-25T18:06:12.245Z

Reserved: 2024-10-24T19:46:19.112Z

Link: CVE-2024-10371

cve-icon Vulnrichment

Updated: 2024-10-25T18:05:32.678Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-25T02:15:03.280

Modified: 2024-10-30T14:51:07.863

Link: CVE-2024-10371

cve-icon Redhat

No data.