Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-34221 — Proof-of-concept for CVE-2024-34221: insecure permission vulnerability in SourceCodester Human Resource Management System 1.0 allowing unauthorized position creation via /hrm/controller/ccity.php. | Kitploit
Tools/GitHubGitHub/dovankha/cve-2024-34221
Vulnerability AnalysisWeb Application ExploitationWeb SecurityPenetration TestingMisconfiguration
GitHubdovankha/cve-2024-34221

CVE-2024-34221

Proof-of-concept for CVE-2024-34221: insecure permission vulnerability in SourceCodester Human Resource Management System 1.0 allowing unauthorized position creation via /hrm/controller/ccity.php.

View Repository
22 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Human Resource Management System Project in PHP and MySQL Free Source Code

Submitter: Kha Do

Vulnerability

Insecure permission

Description

There is an insecure permission vulnerability in /hrm/controller/ccity.php?positionedit= in the SourceCodester Human Resource Management System 1.0, allowing attackers to access functions that are not permitted for a normal user.

Affected component

Path URL: /hrm/controller/ccity.php?positionedit=

Parameter: position.php

Impact

The attacker can use normal account to add new position, which is not permitted for a normal user.

POC

https://github.com/dovankha/CVE-2024-34221/assets/63991630/667ddbd4-af03-4959-9f20-765e9e8a8bae

Download Tool