CVE-2024-10021: code-projects Pharmacy Management System manage_purchase.php sql injection
Published Oct 16, 2024
·Updated
A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /php/managepurchase.php?action=search&tag=VOUCHERNUMBER. The manipulation of the argument text leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Code-projects Pharmacy Management System=1.0
Event History
Oct 16, 2024
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10021?
The severity of CVE-2024-10021 is rated as critical.
2
How do I fix CVE-2024-10021?
To fix CVE-2024-10021, update the Pharmacy Management System to the latest version provided by the vendor.
3
What type of vulnerability is CVE-2024-10021?
CVE-2024-10021 is an SQL injection vulnerability.
4
Which software versions are affected by CVE-2024-10021?
CVE-2024-10021 affects version 1.0 of Code-Projects Pharmacy Management System.
5
What file is associated with CVE-2024-10021?
The vulnerability is associated with the file /php/manage_purchase.php.