CVE-2024-11632: code-projects Simple Car Rental System book_car.php sql injection
A vulnerability was found in code-projects Simple Car Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file /bookcar.php. The manipulation of the argument fname/idno/gender/email/phone/location leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "fname" to be affected. Further analysis indicates that other arguments might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11632?
CVE-2024-11632 is classified as a critical vulnerability.
How does CVE-2024-11632 affect the Simple Car Rental System?
CVE-2024-11632 affects an unknown function in the file /book_car.php, leading to SQL injection vulnerabilities.
What impact does CVE-2024-11632 have on data security?
CVE-2024-11632 allows attackers to manipulate input arguments to execute unauthorized SQL commands, potentially exposing sensitive data.
How can I mitigate CVE-2024-11632?
To mitigate CVE-2024-11632, validate and sanitize all user inputs before processing within the application.
Which version of Simple Car Rental System is affected by CVE-2024-11632?
CVE-2024-11632 affects Simple Car Rental System version 1.0.