SQL Injection Vulnerability in HRMS 1.0 Allows Arbitrary SQL Commands via Password Parameter
CVE-2024-35468

5.4MEDIUM

Key Information:

Vendor
CVE Published:
30 May 2024

Summary

A critical SQL injection flaw exists in the SourceCodester Human Resource Management System version 1.0, specifically within the /hrm/index.php file. This vulnerability enables malicious actors to manipulate the application’s SQL queries through crafted payloads in the password parameter. By exploiting this weakness, attackers can potentially execute arbitrary SQL commands, leading to unauthorized data access and manipulation within the database. Prompt patching and adherence to secure coding practices are essential to mitigate this risk and protect sensitive information from exploitation.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.