CVE-2024-2265
MEDIUMDescription
A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. This affects an unknown part of the file login.sql. The manipulation leads to inclusion of sensitive information in source code. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256035. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Is your site exposed to CVE-2024-2265?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| keerti1924 | php_mysql_user_signup_login_system |
References
Exploits
Frequently Asked Questions
What is CVE-2024-2265? +
How severe is CVE-2024-2265? +
What products are affected by CVE-2024-2265? +
How do I check if I'm vulnerable to CVE-2024-2265? +
Related Vulnerabilities
PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are …
A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may …
An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code …
Inclusion of Sensitive Information in Source Code vulnerability in TNB Mobile Solutions Cockpit Software allows Retrieve Embedded Sensitive Data.This issue …
An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive …