SQL Injection Vulnerability in SourceCodester Best Employee Management System
CVE-2024-11213
7.2HIGH
What is CVE-2024-11213?
A vulnerability exists within the SourceCodester Best Employee Management System version 1.0, specifically in the /admin/edit_role.php file, where improper validation of the 'id' argument allows for SQL injection. This security flaw enables remote attackers to manipulate SQL queries, potentially leading to unauthorized access to sensitive data or compromising backend databases. As this vulnerability has been publicly disclosed, it poses a significant risk for organizations that continue to utilize this affected version of the software. Immediate remediation and updates are advised to mitigate the risks.