SQL Injection Vulnerability in Employee Management System
CVE-2024-25239
9.8CRITICAL
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 21 March 2024
What is CVE-2024-25239?
The SQL Injection vulnerability in Sourcecodester's Employee Management System v1.0 allows attackers to exploit the /emloyee_akpoly/Account/login.php endpoint. By sending specially crafted POST requests, unauthorized users can execute arbitrary SQL commands, potentially leading to unauthorized access to sensitive data and further exploitation of the system. It is essential for administrators to apply patches, verify security measures, and implement input validation to mitigate this risk.
