First published: Mon Jan 29 2024(Updated: )
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file edit_profile.php. The manipulation of the argument txtfullname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252276.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Employee Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1007 has been classified as critical due to the potential for SQL injection.
To fix CVE-2024-1007, it is recommended to sanitize user inputs and utilize prepared statements in the code.
CVE-2024-1007 specifically affects SourceCodester Employee Management System version 1.0.
CVE-2024-1007 is an SQL injection vulnerability that can be exploited through the edit_profile.php file.
Yes, CVE-2024-1007 can be exploited remotely, allowing attackers to manipulate the argument txtfullname.