SQL Injection Vulnerability in SourceCodester Employee and Visitor Gate Pass Logging System
CVE-2024-7069
Key Information:
- Vendor
- Sourcecodester
- Vendor
- CVE Published:
- 24 July 2024
Badges
Summary
A critical vulnerability has been identified in the SourceCodester Employee and Visitor Gate Pass Logging System version 1.0, specifically within the file processing function located at /employee_gatepass/classes/Master.php?f=delete_department. The vulnerability arises from improper validation of input parameters, allowing a malicious actor to manipulate the 'id' argument and execute SQL injection attacks remotely. This exposes sensitive data and compromises the integrity of the system. The exploitation of this vulnerability has been publicly disclosed, highlighting the urgency for users to implement security measures to mitigate potential risks. For further details on this vulnerability, please refer to VDB-272351.
Affected Version(s)
Employee and Visitor Gate Pass Logging System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved