SQL Injection Vulnerability in SourceCodester Computer Laboratory Management System
CVE-2024-8346
9.8CRITICAL
Key Information:
- Vendor
SourceCodester
- Vendor
- CVE Published:
- 30 August 2024
What is CVE-2024-8346?
A critical SQL injection vulnerability has been identified in the SourceCodester Computer Laboratory Management System version 1.0. The flaw lies within the function 'update_settings_info' located in the '/classes/SystemSettings.php' file, where the manipulation of the 'name' argument allows attackers to execute malicious SQL queries. This vulnerability can be exploited remotely, resulting in unauthorized access to sensitive data. Given the public disclosure of this exploit, it is crucial for users of the affected system to implement immediate security measures to mitigate potential risks.