CVE-2024-24572

CVSS V2 None CVSS V3 None
Description
facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, the $_REQUEST global array was unsafely called inside an extract() function in admin-logs.php. The PHP file fm-init.php prevents arbitrary manipulation of $_SESSION via the GET/POST parameters. However, it does not prevent manipulation of any other sensitive variables such as $search_sql. Knowing this, an authenticated user with privileges to view site logs can manipulate the search_sql variable by appending a GET parameter search_sql in the URL. The information above means that the checks and SQL injection prevention attempts were rendered unusable.
Overview
  • CVE ID
  • CVE-2024-24572
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-01-31T22:33:08.498Z
  • Last Modified Date
  • 2024-01-31T22:33:08.498Z
History
Created Old Value New Value Data Type Notes
2024-06-26 04:14:35 Added to TrackCVE