SQL Injection Vulnerability in SourceCodester Lot Reservation Management System
CVE-2024-7281
Key Information:
- Vendor
- Sourcecodester
- Vendor
- CVE Published:
- 31 July 2024
Badges
Summary
A serious SQL injection vulnerability exists in the SourceCodester Lot Reservation Management System version 1.0. This security flaw is located in the /admin/index.php?page=manage_lot file, where improper handling of the 'id' argument allows attackers to execute arbitrary SQL commands. Exploiting this vulnerability can enable unauthorized remote access to the application, potentially leading to data breaches, unauthorized data manipulation, and other malicious activities. With public disclosure of the exploit, it poses an immediate threat to users of the affected product. It is crucial for users to assess their systems and apply appropriate security measures to mitigate risks.
Affected Version(s)
Lot Reservation Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved