SQL Injection Vulnerability in HRMS 1.0 Allows Arbitrary SQL Commands via Password Parameter
CVE-2024-35468
5.4MEDIUM
Key Information:
- Vendor
- SourceCodester
- Vendor
- CVE Published:
- 30 May 2024
Summary
A critical SQL injection flaw exists in the SourceCodester Human Resource Management System version 1.0, specifically within the /hrm/index.php file. This vulnerability enables malicious actors to manipulate the application’s SQL queries through crafted payloads in the password parameter. By exploiting this weakness, attackers can potentially execute arbitrary SQL commands, leading to unauthorized data access and manipulation within the database. Prompt patching and adherence to secure coding practices are essential to mitigate this risk and protect sensitive information from exploitation.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published