SQL Injection Vulnerability in SourceCodester Music Gallery Site
CVE-2024-8221
Key Information:
- Vendor
- Sourcecodester
- Status
- Vendor
- CVE Published:
- 27 August 2024
Badges
Summary
A significant vulnerability has been identified in version 1.0 of the SourceCodester Music Gallery Site, specifically in the manage_category.php file located within the admin directory. Exploiting this vulnerability involves the improper handling of the 'id' argument, leading to SQL injection attacks. This flaw allows attackers to manipulate database queries, potentially allowing unauthorized access to sensitive data. The vulnerability can be exploited remotely, making systems running this software particularly susceptible to attacks. As the exploit has been publicly disclosed, it is crucial for users and administrators of affected products to take immediate actions to remediate this security issue.
Affected Version(s)
Music Gallery Site 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved