Vulnerability CVE-2024-35353


Published: 2024-05-30

Description:
A vulnerability has been discovered in Di??o Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Users.php?f=save. Manipulating the argument id can result in improper authorization.

 References:
https://vuln.pentester.stream/pentester-vulnerability-research/post/2298777/vuln8-insecure-direct-object-references-idor

Copyright 2026, cxsecurity.com

 

Back to Top