SQL Injection Vulnerability Affecting SourceCodester Todo List in Kanban Board
CVE-2024-2934
Key Information:
- Vendor
- Sourcecodester
- Vendor
- CVE Published:
- 27 March 2024
Badges
Summary
A security weakness has been discovered in SourceCodester's Todo List application, specifically within the delete-todo.php functionality. This vulnerability allows attackers to manipulate input arguments, leading to unauthorized SQL commands being executed in the database. This SQL injection flaw can be exploited remotely, posing a significant risk to applications that utilize this version of the software. As this vulnerability has been made public, it is crucial for organizations using this application to apply the necessary patches to mitigate potential attacks.
Affected Version(s)
Todo List in Kanban Board 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved