SQL Injection Vulnerability in SourceCodester Tracking Monitoring Management System
CVE-2024-7361

9.8CRITICAL

Key Information:

Vendor

Oretnom23

Vendor
CVE Published:
1 August 2024

What is CVE-2024-7361?

A critical vulnerability has been identified in the SourceCodester Tracking Monitoring Management System, specifically within the /ajax.php?action=save_establishment endpoint. This flaw allows an attacker to manipulate the 'id' parameter, which can lead to SQL injection attacks. Such vulnerabilities are particularly severe as they can enable unauthorized access to sensitive data stored in the database. The attack can be initiated remotely, making it even more critical for users to patch their systems to avoid potential exploitation. Active engagements have been disclosed publicly, highlighting the need for prompt remediation to safeguard affected applications.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.