Medium severity6.3NVD Advisory· Published Mar 7, 2024· Updated Jun 17, 2026
CVE-2024-26492
CVE-2024-26492
Description
An issue in Online Diagnostic Lab Management System 1.0 allows a remote attacker to gain control of a 'Staff' user account via a crafted POST request using the id, email, password, and cpass parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:oretnom23:online_diagnostic_lab_management_system:1.0:*:*:*:*:*:*:*
- Online Diagnostic Lab Management System/Online Diagnostic Lab Management Systemdescription
- Range: = 1.0
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/165555/Online-Diagnostic-Lab-Management-System-1.0-Missing-Access-Control.htmlnvdExploitThird Party Advisory
- www.exploit-db.com/exploits/50660nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.