SQL Injection Vulnerability in itsourcecode Online House Rental System
CVE-2024-6015
Key Information:
- Vendor
- Itsourcecode
- Vendor
- CVE Published:
- 15 June 2024
Badges
Summary
A significant SQL injection vulnerability has been identified in the itsourcecode Online House Rental System version 1.0, specifically within the manage_user.php file. This vulnerability arises due to improper handling of the 'month_of' argument, allowing attackers to manipulate database queries executed by the application. The exploiting of this vulnerability enables unauthorized access and potential data disclosure, posing serious risks to the security of the affected system. Notably, this flaw can be exploited remotely, making it imperative for users of the affected product to take immediate action to safeguard their applications.
Affected Version(s)
Online House Rental System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved