CVE-2024-10990: SourceCodester Online Veterinary Appointment System view_service.php sql injection
A vulnerability classified as critical was found in SourceCodester Online Veterinary Appointment System 1.0. This vulnerability affects unknown code of the file /admin/services/viewservice.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10990?
CVE-2024-10990 is classified as a critical vulnerability.
How does CVE-2024-10990 exploit SQL injection?
CVE-2024-10990 exploits SQL injection by manipulating the 'id' argument in /admin/services/view_service.php.
What systems are affected by CVE-2024-10990?
CVE-2024-10990 affects version 1.0 of the Oretnom23 Online Veterinary Appointment System.
How can I fix CVE-2024-10990?
To fix CVE-2024-10990, validate and sanitize all user inputs to prevent SQL injection.
What should I do if I am using the affected software with CVE-2024-10990?
If using the affected software with CVE-2024-10990, immediately implement security measures and seek updated software patches.