📦

daily_habit_tracker

Vendor: remyandrade

Actively Exploited 0 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 2 Remote Access
Total CVEs 5 Total Indexed
Avg. EPSS 9.68% Exploit Prob.
Latest CVE CVE-2024-2075 Mar 01

Security Vulnerability Index

Page 1 / 1
3.5 CVSS

A vulnerability was found in SourceCodester Daily Habit Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/update-tracker.php. The manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-255391.

EPSS: 0.54%
9.8 CVSS
CVE-2024-24496
Exploit Found

An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.

EPSS: 19.50%
9.8 CVSS
CVE-2024-24495
RCE Exploit Found

SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.

EPSS: 1.33%
6.1 CVSS
CVE-2024-24494
RCE Exploit Found

Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.

EPSS: 25.88%
7.2 CVSS
CVE-2024-24140
Exploit Found

Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'

EPSS: 1.16%