CVE-2024-11632: code-projects Simple Car Rental System book_car.php sql injection

Published Nov 23, 2024
·
Updated

A vulnerability was found in code-projects Simple Car Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file /bookcar.php. The manipulation of the argument fname/idno/gender/email/phone/location leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "fname" to be affected. Further analysis indicates that other arguments might be affected as well.

Affected Software

1 affected component
Fabian Simple Car Rental System=1.0

Event History

Nov 23, 2024
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-11632?

CVE-2024-11632 is classified as a critical vulnerability.

2

How does CVE-2024-11632 affect the Simple Car Rental System?

CVE-2024-11632 affects an unknown function in the file /book_car.php, leading to SQL injection vulnerabilities.

3

What impact does CVE-2024-11632 have on data security?

CVE-2024-11632 allows attackers to manipulate input arguments to execute unauthorized SQL commands, potentially exposing sensitive data.

4

How can I mitigate CVE-2024-11632?

To mitigate CVE-2024-11632, validate and sanitize all user inputs before processing within the application.

5

Which version of Simple Car Rental System is affected by CVE-2024-11632?

CVE-2024-11632 affects Simple Car Rental System version 1.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203