SQL Injection Vulnerability in Campcodes Online Laundry Management System
CVE-2024-4793
Key Information:
- Vendor
- Campcodes
- Status
- Online Laundry Management System
- Vendor
- CVE Published:
- 14 May 2024
Badges
Summary
A serious SQL Injection vulnerability has been identified in the Campcodes Online Laundry Management System version 1.0, specifically within the /manage_laundry.php file. This flaw allows an attacker to manipulate the 'id' parameter, which can lead to unauthorized access and potential manipulation of the backend database. Because the vulnerability can be exploited remotely, it poses a significant risk to users of this software. Public disclosure of this vulnerability has raised concerns, prompting an immediate need for affected users to implement security measures to mitigate this risk.
Affected Version(s)
Online Laundry Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved