SQL Injection Vulnerability in SourceCodester Computer Laboratory Management System
CVE-2024-8346

9.8CRITICAL

Key Information:

Vendor
CVE Published:
30 August 2024

Summary

A critical SQL injection vulnerability has been identified in the SourceCodester Computer Laboratory Management System version 1.0. The flaw lies within the function 'update_settings_info' located in the '/classes/SystemSettings.php' file, where the manipulation of the 'name' argument allows attackers to execute malicious SQL queries. This vulnerability can be exploited remotely, resulting in unauthorized access to sensitive data. Given the public disclosure of this exploit, it is crucial for users of the affected system to implement immediate security measures to mitigate potential risks.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.