code-projects Blood Bank Management System 1.0 Password Obelodanjivanje informacija

Otkrivena je ranjivost klasifikovana kao Problematiиno u code-projects Blood Bank Management System 1.0. Pogođeno je nepoznata funkcija u komponenti Password Handler. Manipulacija dovodi do Obelodanjivanje informacija. Korišćenjem CWE za opis problema dolazi se do CWE-313. Slabost je objavljena 09/20/2024. Ova ranjivost je poznata pod oznakom CVE-2024-9040. Za sprovođenje napada neophodan je lokalni pristup. Tehnički podaci nisu dostupni. Додатно, постоји доступан експлоит. Trenutna cena za eksploataciju može biti približno USD $0-$5k u ovom trenutku. Prema MITRE ATT&CK projektu, tehnika napada je T1555. Definisano je kao dokaz-of-koncept. Kao 0-day, očekivana cena na crnom tržištu bila je oko $0-$5k. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.

4 Promene · 81 Tačke podataka

PoljeKreirali
09/20/2024 10:37
Ažurira 1/3
09/21/2024 15:58
Ažurira 2/3
09/27/2024 05:02
Ažurira 3/3
09/28/2024 13:21
software_vendorcode-projectscode-projectscode-projectscode-projects
software_nameBlood Bank Management SystemBlood Bank Management SystemBlood Bank Management SystemBlood Bank Management System
software_version1.01.01.01.0
software_componentPassword HandlerPassword HandlerPassword HandlerPassword Handler
vulnerability_cweCWE-313CWE-313CWE-313CWE-313
vulnerability_risk1111
cvss3_vuldb_avLLLL
cvss3_vuldb_acLLLL
cvss3_vuldb_prHHHH
cvss3_vuldb_uiNNNN
cvss3_vuldb_sUUUU
cvss3_vuldb_cLLLL
cvss3_vuldb_iNNNN
cvss3_vuldb_aNNNN
cvss3_vuldb_rcRRRR
exploit_availability1111
source_cveCVE-2024-9040CVE-2024-9040CVE-2024-9040CVE-2024-9040
cna_responsibleVulDBVulDBVulDBVulDB
software_typeBanking SoftwareBanking SoftwareBanking SoftwareBanking Software
cvss2_vuldb_avLLLL
cvss2_vuldb_acLLLL
cvss2_vuldb_auMMMM
cvss2_vuldb_ciPPPP
cvss2_vuldb_iiNNNN
cvss2_vuldb_aiNNNN
cvss2_vuldb_rcURURURUR
cvss4_vuldb_avLLLL
cvss4_vuldb_acLLLL
cvss4_vuldb_prHHHH
cvss4_vuldb_uiNNNN
cvss4_vuldb_vcLLLL
cvss4_vuldb_viNNNN
cvss4_vuldb_vaNNNN
cvss2_vuldb_eNDNDNDND
cvss2_vuldb_rlNDNDNDND
cvss3_vuldb_eXXXX
cvss3_vuldb_rlXXXX
cvss4_vuldb_atNNNN
cvss4_vuldb_scNNNN
cvss4_vuldb_siNNNN
cvss4_vuldb_saNNNN
cvss4_vuldb_eXXXX
cvss2_vuldb_basescore1.41.41.41.4
cvss2_vuldb_tempscore1.31.31.31.3
cvss3_vuldb_basescore2.32.32.32.3
cvss3_vuldb_tempscore2.32.32.32.3
cvss3_meta_basescore2.32.32.33.4
cvss3_meta_tempscore2.32.32.33.4
cvss4_vuldb_bscore4.64.64.64.6
cvss4_vuldb_btscore4.64.64.64.6
advisory_date1726783200 (09/20/2024)1726783200 (09/20/2024)1726783200 (09/20/2024)1726783200 (09/20/2024)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k
cve_nvd_summaryA vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the component Password Handler. The manipulation leads to cleartext storage in a file or on disk. An attack has to be approached locally.A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the component Password Handler. The manipulation leads to cleartext storage in a file or on disk. An attack has to be approached locally.A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the component Password Handler. The manipulation leads to cleartext storage in a file or on disk. An attack has to be approached locally.
cvss3_cna_avLLL
cvss3_cna_acLLL
cvss3_cna_prHHH
cvss3_cna_uiNNN
cvss3_cna_sUUU
cvss3_cna_cLLL
cvss3_cna_iNNN
cvss3_cna_aNNN
cvss3_cna_basescore2.32.32.3
cvss2_cna_avLLL
cvss2_cna_acLLL
cvss2_cna_auMMM
cvss2_cna_ciPPP
cvss2_cna_iiNNN
cvss2_cna_aiNNN
cvss2_cna_basescore1.41.41.4
cve_nvd_summaryesEn code-projects Blood Bank Management System 1.0 se ha detectado una vulnerabilidad clasificada como problemática. Afecta a una parte desconocida del componente Password Handler. La manipulación provoca el almacenamiento de texto plano en un archivo o en un disco. El ataque debe abordarse localmente.En code-projects Blood Bank Management System 1.0 se ha detectado una vulnerabilidad clasificada como problemática. Afecta a una parte desconocida del componente Password Handler. La manipulación provoca el almacenamiento de texto plano en un archivo o en un disco. El ataque debe abordarse localmente.
cvss3_nvd_avL
cvss3_nvd_acL
cvss3_nvd_prL
cvss3_nvd_uiN
cvss3_nvd_sU
cvss3_nvd_cH
cvss3_nvd_iN
cvss3_nvd_aN
cvss3_nvd_basescore5.5

Interested in the pricing of exploits?

See the underground prices here!