CVE-2023-24204: SQL Injection
Published May 14, 2024
·Updated
SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.
Affected Software
2 affected components
Sourcecodester Simple Customer Relationship Management System
oretnom23 Simple Customer Relationship Management System=1.0
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·05:15 PM
Oct 31, 2024
Data Sourced
via MITRE·03:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-24204?
CVE-2023-24204 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2023-24204?
To mitigate CVE-2023-24204, sanitize user inputs and utilize prepared statements in database queries.
3
What systems are affected by CVE-2023-24204?
CVE-2023-24204 affects SourceCodester Simple Customer Relationship Management System version 1.0.
4
What type of vulnerability is CVE-2023-24204?
CVE-2023-24204 is an SQL injection vulnerability that allows arbitrary code execution.
5
Can CVE-2023-24204 be exploited remotely?
Yes, CVE-2023-24204 can be exploited remotely through the affected application's parameters.