First published: Mon Feb 26 2024(Updated: )
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid with the input '+or+1%3d1%23 leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254724.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Employee Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1876 has been classified as critical due to its potential for SQL injection exploitation.
CVE-2024-1876 affects the Employee Management System 1.0 through an insecurity in the /psubmit.php file allowing SQL injection.
To fix CVE-2024-1876, sanitize and validate user input to prevent SQL injection vulnerabilities.
Exploiting CVE-2024-1876 could allow attackers to manipulate the database, extract sensitive information, or disrupt system integrity.
CVE-2024-1876 specifically affects users of the SourceCodester Employee Management System version 1.0.