SQL Injection Vulnerability in SourceCodester Computer Laboratory Management System
CVE-2024-8346
9.8CRITICAL
Key Information:
- Vendor
- SourceCodester
- Vendor
- CVE Published:
- 30 August 2024
Summary
A critical SQL injection vulnerability has been identified in the SourceCodester Computer Laboratory Management System version 1.0. The flaw lies within the function 'update_settings_info' located in the '/classes/SystemSettings.php' file, where the manipulation of the 'name' argument allows attackers to execute malicious SQL queries. This vulnerability can be exploited remotely, resulting in unauthorized access to sensitive data. Given the public disclosure of this exploit, it is crucial for users of the affected system to implement immediate security measures to mitigate potential risks.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published