SQL Injection Vulnerability in SourceCodester Prison Management System
CVE-2024-3438
Key Information:
- Vendor
- Sourcecodester
- Status
- Vendor
- CVE Published:
- 8 April 2024
Badges
Summary
A critical SQL injection vulnerability has been identified in version 1.0 of the SourceCodester Prison Management System. This vulnerability occurs in the /Admin/login.php file, allowing an attacker to execute arbitrary SQL queries by manipulating parameters. The exploitation of this vulnerability can be initiated remotely, posing significant risks to the confidentiality and integrity of the system's database. Public disclosure of the exploit has raised concerns about its potential misuse. Organizations using this system must take immediate steps to implement security measures and update their systems to mitigate the risk.
Affected Version(s)
Prison Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved