{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-5981","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2024-06-13T18:06:12.807Z","datePublished":"2024-06-14T01:00:04.079Z","dateUpdated":"2024-08-01T21:25:03.202Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-06-14T01:00:04.079Z"},"title":"itsourcecode Online House Rental System manage_user.php sql injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-89","lang":"en","description":"CWE-89 SQL Injection"}]}],"affected":[{"vendor":"itsourcecode","product":"Online House Rental System","versions":[{"version":"1.0","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in itsourcecode Online House Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-268458 is the identifier assigned to this vulnerability."},{"lang":"de","value":"Es wurde eine kritische Schwachstelle in itsourcecode Online House Rental System 1.0 ausgemacht. Dabei betrifft es einen unbekannter Codeteil der Datei manage_user.php. Durch die Manipulation des Arguments id mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":6.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":6.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":6.5,"vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P"}}],"timeline":[{"time":"2024-06-13T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2024-06-13T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-06-13T20:11:20.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"dlss (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.268458","name":"VDB-268458 | itsourcecode Online House Rental System manage_user.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.268458","name":"VDB-268458 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.356163","name":"Submit #356163 | itsourcecode Online House Rental System Project In PHP 1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LiuYongXiang-git/cve/issues/1","tags":["exploit","issue-tracking"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-06-14T18:12:05.698241Z","id":"CVE-2024-5981","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-14T18:12:12.494Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T21:25:03.202Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.268458","name":"VDB-268458 | itsourcecode Online House Rental System manage_user.php sql injection","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.268458","name":"VDB-268458 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required","x_transferred"]},{"url":"https://vuldb.com/?submit.356163","name":"Submit #356163 | itsourcecode Online House Rental System Project In PHP 1.0 SQL Injection","tags":["third-party-advisory","x_transferred"]},{"url":"https://github.com/LiuYongXiang-git/cve/issues/1","tags":["exploit","issue-tracking","x_transferred"]}]}]}}