CVE-2024-10380: SourceCodester Petrol Pump Management Software ajax_product.php sql injection
A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/ajaxproduct.php. The manipulation of the argument dropservices leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10380?
CVE-2024-10380 is classified as a critical vulnerability.
What is the impact of CVE-2024-10380?
CVE-2024-10380 allows for SQL injection through the manipulation of the drop_services argument in /admin/ajax_product.php.
How do I fix CVE-2024-10380?
To fix CVE-2024-10380, it is recommended to sanitize and validate user input in the affected file to mitigate SQL injection risks.
Which software is affected by CVE-2024-10380?
CVE-2024-10380 affects SourceCodester Petrol Pump Management Software version 1.0.
What should I do if I cannot patch CVE-2024-10380 immediately?
If immediate patching is not possible for CVE-2024-10380, implement web application firewall rules to block potential SQL injection attempts as a temporary measure.