SQL Injection Vulnerability in SourceCodester Aplaya Beach Resort Online Reservation System
CVE-2024-3355
9.8CRITICAL
What is CVE-2024-3355?
A vulnerability affecting the SourceCodester Aplaya Beach Resort Online Reservation System 1.0 allows an attacker to exploit a flaw in the administration functionality located in the file admin/mod_users/controller.php. By manipulating the input parameter 'name' during the user creation process, an attacker can execute SQL injection, potentially gaining unauthorized access to the database. This exploitation can occur remotely, and since the vulnerability has been made public, it poses a significant risk. Users of this system should take immediate action to mitigate the threat by applying security patches and reviewing their database configurations.