SQL Injection Vulnerability in SourceCodester Kortex Lite Advocate Office Management System
CVE-2024-7639
Key Information:
- Vendor
- Sourcecodester
- Status
- Kortex Lite Advocate Office Management System
- Vendor
- CVE Published:
- 12 August 2024
Badges
Summary
A severe SQL injection vulnerability has been identified in the SourceCodester Kortex Lite Advocate Office Management System version 1.0. The flaw resides in the delete_act.php file, where improper handling of the 'id' parameter allows remote attackers to execute arbitrary SQL queries against the database. This can lead to unauthorized data access, modification, or even complete system compromise. The vulnerability has been publicly disclosed, heightening the risk for users who have not yet applied recommended security patches or mitigations. It is crucial for organizations utilizing this software to take immediate action to safeguard their systems.
Affected Version(s)
Kortex Lite Advocate Office Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved