First published: Wed Sep 09 2020(Updated: )
A SQL injection vulnerability in the login component in Stock Management System v1.0 allows remote attacker to execute arbitrary SQL commands via the username parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stock Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24197 is a SQL injection vulnerability in the login component of Stock Management System v1.0.
CVE-2020-24197 allows a remote attacker to execute arbitrary SQL commands via the username parameter of the login component.
CVE-2020-24197 has a severity rating of 9.8, which is considered critical.
To fix CVE-2020-24197, you should update the Stock Management System to a version that has addressed the SQL injection vulnerability.
You can find more information about CVE-2020-24197 at the following references: - [CXSecurity](https://cxsecurity.com/issue/WLB-2020090028) - [Source Codester](https://www.sourcecodester.com/php/14366/stock-management-system-php.html)