{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-11673","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2024-11-25T14:36:07.680Z","datePublished":"2024-11-25T23:00:14.123Z","dateUpdated":"2024-11-26T15:21:45.286Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-11-25T23:00:14.123Z"},"title":"1000 Projects Bookstore Management System cross-site request forgery","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-352","lang":"en","description":"Cross-Site Request Forgery"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-862","lang":"en","description":"Missing Authorization"}]}],"affected":[{"vendor":"1000 Projects","product":"Bookstore Management System","versions":[{"version":"1.0","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A vulnerability, which was classified as problematic, has been found in 1000 Projects Bookstore Management System 1.0. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used."},{"lang":"de","value":"Eine Schwachstelle wurde in 1000 Projects Bookstore Management System 1.0 entdeckt. Sie wurde als problematisch eingestuft. Betroffen davon ist ein unbekannter Prozess. Mit der Manipulation mit unbekannten Daten kann eine cross-site request forgery-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":6.9,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":4.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":4.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":5,"vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N"}}],"timeline":[{"time":"2024-11-25T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2024-11-25T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-11-25T15:41:23.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"polaris0x1 (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.286013","name":"VDB-286013 | 1000 Projects Bookstore Management System cross-site request forgery","tags":["vdb-entry"]},{"url":"https://vuldb.com/?ctiid.286013","name":"VDB-286013 | CTI Indicators (IOB, IOC)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.448470","name":"Submit #448470 | 1000 Projects Bookstore Management System PHP MySQL Project V1.0 Cross-Site Request Forgery","tags":["third-party-advisory"]},{"url":"https://github.com/Hacker0xone/CVE/issues/16","tags":["exploit","issue-tracking"]},{"url":"https://1000projects.org/","tags":["product"]}]},"adp":[{"affected":[{"vendor":"1000projects","product":"bookstore_management_system","cpes":["cpe:2.3:a:1000projects:bookstore_management_system:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1.0","status":"affected"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-11-26T15:21:07.345953Z","id":"CVE-2024-11673","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-11-26T15:21:45.286Z"}}]}}