SQL Injection Flaw in SourceCodester Complete File Management System Admin Login
CVE-2024-1832
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 23 February 2024
Badges
What is CVE-2024-1832?
A significant vulnerability has been identified in the SourceCodester Complete File Management System, specifically within the Admin Login Form component. This flaw allows an attacker to perform SQL injection by manipulating the 'username' parameter with specially crafted input. As a result, an unauthorized individual could gain access to restricted admin functionalities, potentially compromising sensitive data and system integrity. This vulnerability can be exploited remotely, raising serious security concerns for users of the affected product. Immediate action is advised to mitigate potential risks associated with this level of exploitation.
Affected Version(s)
Complete File Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
