facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, the $_REQUEST global array was unsafely called inside an extract() function in admin-logs.php. The PHP file fm-init.php prevents arbitrary manipulation of $_SESSION via the GET/POST parameters. However, it does not prevent manipulation of any other sensitive variables such as $search_sql. Knowing this, an authenticated user with privileges to view site logs can manipulate the search_sql
variable by appending a GET parameter search_sql in the URL. The information above means that the checks and SQL injection prevention attempts were rendered unusable.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 17 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-10-17T17:08:31.130Z

Reserved: 2024-01-25T15:09:40.211Z

Link: CVE-2024-24572

cve-icon Vulnrichment

Updated: 2024-08-01T23:19:52.906Z

cve-icon NVD

Status : Modified

Published: 2024-01-31T23:15:08.337

Modified: 2024-11-21T08:59:26.877

Link: CVE-2024-24572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.