SQL Injection Vulnerability in SourceCodester Tracking Monitoring Management System 1.0
CVE-2024-7364

9.8CRITICAL

Key Information:

Vendor

Oretnom23

Vendor
CVE Published:
1 August 2024

What is CVE-2024-7364?

A SQL injection vulnerability has been identified in the SourceCodester Tracking Monitoring Management System version 1.0, specifically within the /manage_records.php file. The vulnerability arises from improper handling of the 'id' parameter, allowing attackers to manipulate SQL queries executed on the backend database. This exploit can be executed remotely, potentially leading to unauthorized access to sensitive data stored within the system. As this vulnerability has been disclosed to the public, it poses a significant risk to all installations of the affected software, making immediate remediation a priority for security teams.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.