
CVE-2024-34221の概念実証:SourceCodester Human Resource Management System 1.0の安全でない権限脆弱性。/hrm/controller/ccity.phpを介した承認されていない役職作成を可能にします。
安全でない権限
SourceCodester Human Resource Management System 1.0の/hrm/controller/ccity.php?positionedit=に安全でない権限の脆弱性が存在し、攻撃者が一般ユーザーには許可されていない機能にアクセスできる可能性があります。
パスURL: /hrm/controller/ccity.php?positionedit=
パラメータ: position.php
攻撃者は一般アカウントを使用して新しい役職を追加でき、これは一般ユーザーには許可されていません。
https://github.com/dovankha/CVE-2024-34221/assets/63991630/667ddbd4-af03-4959-9f20-765e9e8a8bae