First published: Sun Oct 20 2024(Updated: )
A vulnerability was found in SourceCodester Sentiment Based Movie Rating System 1.0. It has been classified as critical. Affected is an unknown function of the file /msrps/movie_details.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher disclosure mentions a slightly changed product name.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Sentiment Based Movie Rating System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10163 has been classified as a critical vulnerability.
CVE-2024-10163 is an SQL injection vulnerability.
CVE-2024-10163 affects the movie_details.php file within the SourceCodester Sentiment Based Movie Rating System 1.0.
To fix CVE-2024-10163, validate and sanitize user inputs, particularly the 'id' parameter.
CVE-2024-10163 can potentially allow an attacker to execute arbitrary SQL commands on the database.