SQL Injection Vulnerability in Sourcecodester Cab Management System by Sourcecodester
CVE-2024-51030

6.5MEDIUM

Key Information:

Vendor

Oretnom23

Vendor
CVE Published:
8 November 2024

What is CVE-2024-51030?

The Sourcecodester Cab Management System version 1.0 contains a SQL injection vulnerability located in manage_client.php and view_cab.php. This vulnerability enables remote attackers to manipulate SQL queries by injecting arbitrary SQL code through the 'id' parameter, potentially granting unauthorized access to sensitive data stored in the database. Exploiting this vulnerability could lead to data leakage, loss of integrity, and a significant risk to user privacy. It is essential for users of this system to apply remediations promptly to safeguard their data.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.