SQL Injection Vulnerability in HRMS 1.0 Allows Arbitrary SQL Commands via Password Parameter
CVE-2024-35468
Key Information:
- Vendor
SourceCodester
- Vendor
- CVE Published:
- 30 May 2024
What is CVE-2024-35468?
A critical SQL injection flaw exists in the SourceCodester Human Resource Management System version 1.0, specifically within the /hrm/index.php file. This vulnerability enables malicious actors to manipulate the application’s SQL queries through crafted payloads in the password parameter. By exploiting this weakness, attackers can potentially execute arbitrary SQL commands, leading to unauthorized data access and manipulation within the database. Prompt patching and adherence to secure coding practices are essential to mitigate this risk and protect sensitive information from exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
