CVE-2024-10355: SourceCodester Petrol Pump Management Software invoice.php sql injection
A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/invoice.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10355?
CVE-2024-10355 has been classified as a critical vulnerability.
How do I fix CVE-2024-10355?
To fix CVE-2024-10355, it is recommended to update to a patched version of the SourceCodester Petrol Pump Management Software.
What type of vulnerability is CVE-2024-10355?
CVE-2024-10355 is an SQL injection vulnerability.
What is affected by CVE-2024-10355?
CVE-2024-10355 affects the /admin/invoice.php functionality of the SourceCodester Petrol Pump Management Software version 1.0.
Can CVE-2024-10355 lead to data compromise?
Yes, exploitation of CVE-2024-10355 can lead to unauthorized access to sensitive data through SQL injection.