CVE-2024-10022: code-projects Pharmacy Management System manage_supplier.php sql injection
Published Oct 16, 2024
·Updated
A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/managesupplier.php?action=search. The manipulation of the argument text leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Code-projects Pharmacy Management System=1.0
Event History
Oct 16, 2024
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10022?
CVE-2024-10022 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2024-10022?
CVE-2024-10022 is a SQL injection vulnerability.
3
Which software versions are affected by CVE-2024-10022?
CVE-2024-10022 affects version 1.0 of the code-projects Pharmacy Management System.
4
How do I fix CVE-2024-10022?
To fix CVE-2024-10022, implement parameterized queries to prevent SQL injection.
5
Where is the vulnerable code located for CVE-2024-10022?
The vulnerable code for CVE-2024-10022 is located in /php/manage_supplier.php when handling the search action.