CVE-2024-12186: code-projects Hotel Management System Available Room hotelnew.c stack-based overflow

4.8 CVSS

Description

A vulnerability was found in code-projects Hotel Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file hotelnew.c of the component Available Room Handler. The manipulation of the argument admin_entry leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Eine problematische Schwachstelle wurde in code-projects Hotel Management System 1.0 gefunden. Dies betrifft einen unbekannten Teil der Datei hotelnew.c der Komponente Available Room Handler. Mittels dem Manipulieren des Arguments admin_entry mit unbekannten Daten kann eine stack-based buffer overflow-Schwachstelle ausgenutzt werden. Umgesetzt werden muss der Angriff lokal. Der Exploit steht zur öffentlichen Verfügung.

Classification

CVE ID: CVE-2024-12186

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.8

Affected Products

Vendor: code-projects

Product: Hotel Management System

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 5.06% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://vuldb.com/?id.286907
https://vuldb.com/?ctiid.286907
https://vuldb.com/?submit.454846
https://github.com/1zzan/cve/blob/main/STACK-OVERFLOW2.md
https://code-projects.org/

Timeline