Vulnerability Description
A vulnerability classified as problematic has been found in PHPGurukul Boat Booking System 1.0. Affected is the function session_start. The manipulation leads to session fixiation. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Boat Booking System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/jadu101/CVE/blob/main/phpgurukul_boat_booking_system_session_ExploitThird Party Advisory
- https://phpgurukul.com/Product
- https://vuldb.com/?ctiid.280944Permissions RequiredThird Party AdvisoryVDB Entry
- https://vuldb.com/?id.280944Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.425414Third Party AdvisoryVDB Entry
FAQ
What is CVE-2024-10158?
CVE-2024-10158 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A vulnerability classified as problematic has been found in PHPGurukul Boat Booking System 1.0. Affected is the function session_start. The manipulation leads to session fixiation. It is possible to l...
How severe is CVE-2024-10158?
CVE-2024-10158 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-10158?
Check the references section above for vendor advisories and patch information. Affected products include: Phpgurukul Boat Booking System.