SQL Injection Vulnerability in SourceCodester Car Driving School Management System
CVE-2024-7664
Key Information:
- Vendor
- Sourcecodester
- Status
- Car Driving School Management System
- Vendor
- CVE Published:
- 12 August 2024
Badges
Summary
A critical SQL injection vulnerability has been identified in the SourceCodester Car Driving School Management System version 1.0, specifically within the 'view_details.php' file. This flaw occurs due to improper validation of the 'id' parameter, allowing attackers to manipulate SQL queries. The exploitation can be performed remotely, posing significant risks to user data integrity and system confidentiality. Organizations utilizing this product should take immediate action to assess their systems and implement necessary security measures to mitigate potential attacks. Public knowledge of this exploit increases the urgency for patching and system hardening to avert possible breaches.
Affected Version(s)
Car Driving School Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved