SQL Injection Vulnerability in Code-Projects Library System
CVE-2024-1829
Key Information:
- Vendor
- Code-projects
- Status
- Vendor
- CVE Published:
- 23 February 2024
Badges
Summary
A vulnerability has been identified in the Code-Projects Library System version 1.0, specifically within the registration functionality located in the file 'Source/librarian/user/student/registration.php'. This vulnerability arises from improper handling of user inputs, including email, registration number, phone number, and username, which can lead to SQL injection attacks. Attackers can exploit this flaw remotely to manipulate database queries, potentially allowing unauthorized access to user information or other sensitive data. The details of this exploit have been publicly disclosed, heightening the urgency for users to assess their systems and implement necessary security measures.
Affected Version(s)
Library System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved