Sports Management System Project 1.0 vulnerable to SQL Injection
CVE-2024-46078
7.5HIGH
What is CVE-2024-46078?
The itsourcecode Sports Management System Project 1.0 contains a vulnerability in the 'delete_category' function located in the 'sports_scheduling/player.php' file. This vulnerability allows attackers to exploit the input parameter 'id', facilitating unauthorized access to the database. By executing crafted SQL queries, an attacker could manipulate, modify, or delete data, leading to significant security risks. It is imperative for users to implement immediate corrective measures to secure their systems.
