Vulnerability Details CVE-2024-24572
facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, the $_REQUEST global array was unsafely called inside an extract() function in admin-logs.php. The PHP file fm-init.php prevents arbitrary manipulation of $_SESSION via the GET/POST parameters. However, it does not prevent manipulation of any other sensitive variables such as $search_sql. Knowing this, an authenticated user with privileges to view site logs can manipulate the search_sql
variable by appending a GET parameter search_sql in the URL. The information above means that the checks and SQL injection prevention attempts were rendered unusable.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 48.4%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-24572
-
cpe:2.3:a:facilemanager:facilemanager:1.0
-
cpe:2.3:a:facilemanager:facilemanager:1.0.1
-
cpe:2.3:a:facilemanager:facilemanager:1.0.2
-
cpe:2.3:a:facilemanager:facilemanager:1.1
-
cpe:2.3:a:facilemanager:facilemanager:1.1.1
-
cpe:2.3:a:facilemanager:facilemanager:1.1.2
-
cpe:2.3:a:facilemanager:facilemanager:1.2
-
cpe:2.3:a:facilemanager:facilemanager:1.2.1
-
cpe:2.3:a:facilemanager:facilemanager:1.2.2
-
cpe:2.3:a:facilemanager:facilemanager:1.2.3
-
cpe:2.3:a:facilemanager:facilemanager:1.3
-
cpe:2.3:a:facilemanager:facilemanager:1.3.1
-
cpe:2.3:a:facilemanager:facilemanager:2.0
-
cpe:2.3:a:facilemanager:facilemanager:2.0.1
-
cpe:2.3:a:facilemanager:facilemanager:2.0.2
-
cpe:2.3:a:facilemanager:facilemanager:2.0.3
-
cpe:2.3:a:facilemanager:facilemanager:2.1
-
cpe:2.3:a:facilemanager:facilemanager:2.1.1
-
cpe:2.3:a:facilemanager:facilemanager:2.1.2
-
cpe:2.3:a:facilemanager:facilemanager:2.1.3
-
cpe:2.3:a:facilemanager:facilemanager:2.1.4
-
cpe:2.3:a:facilemanager:facilemanager:2.1.5
-
cpe:2.3:a:facilemanager:facilemanager:2.2
-
cpe:2.3:a:facilemanager:facilemanager:2.2.1
-
cpe:2.3:a:facilemanager:facilemanager:2.3
-
cpe:2.3:a:facilemanager:facilemanager:2.3.1
-
cpe:2.3:a:facilemanager:facilemanager:2.3.2
-
cpe:2.3:a:facilemanager:facilemanager:2.3.3
-
cpe:2.3:a:facilemanager:facilemanager:3.0
-
cpe:2.3:a:facilemanager:facilemanager:3.0.1
-
cpe:2.3:a:facilemanager:facilemanager:3.0.2
-
cpe:2.3:a:facilemanager:facilemanager:3.0.3
-
cpe:2.3:a:facilemanager:facilemanager:3.1.0
-
cpe:2.3:a:facilemanager:facilemanager:3.1.1
-
cpe:2.3:a:facilemanager:facilemanager:3.2
-
cpe:2.3:a:facilemanager:facilemanager:3.3
-
cpe:2.3:a:facilemanager:facilemanager:3.4
-
cpe:2.3:a:facilemanager:facilemanager:3.4.1
-
cpe:2.3:a:facilemanager:facilemanager:3.4.2
-
cpe:2.3:a:facilemanager:facilemanager:3.5.0
-
cpe:2.3:a:facilemanager:facilemanager:3.5.1
-
cpe:2.3:a:facilemanager:facilemanager:3.5.2
-
cpe:2.3:a:facilemanager:facilemanager:3.5.3
-
cpe:2.3:a:facilemanager:facilemanager:3.5.4
-
cpe:2.3:a:facilemanager:facilemanager:3.5.5
-
cpe:2.3:a:facilemanager:facilemanager:3.5.6
-
cpe:2.3:a:facilemanager:facilemanager:3.5.7
-
cpe:2.3:a:facilemanager:facilemanager:4.0.0
-
cpe:2.3:a:facilemanager:facilemanager:4.0.1
-
cpe:2.3:a:facilemanager:facilemanager:4.0.2
-
cpe:2.3:a:facilemanager:facilemanager:4.0.3
-
cpe:2.3:a:facilemanager:facilemanager:4.1.0
-
cpe:2.3:a:facilemanager:facilemanager:4.1.1
-
cpe:2.3:a:facilemanager:facilemanager:4.1.2
-
cpe:2.3:a:facilemanager:facilemanager:4.2.0
-
cpe:2.3:a:facilemanager:facilemanager:4.3.0
-
cpe:2.3:a:facilemanager:facilemanager:4.4.0
-
cpe:2.3:a:facilemanager:facilemanager:4.5.0