CVE-2024-1876: SourceCodester Employee Management System psubmit.php sql injection
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid with the input '+or+1%3d1%23 leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254724.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1876?
CVE-2024-1876 has been classified as critical due to its potential for SQL injection exploitation.
How does CVE-2024-1876 affect the SourceCodester Employee Management System?
CVE-2024-1876 affects the Employee Management System 1.0 through an insecurity in the /psubmit.php file allowing SQL injection.
How do I fix CVE-2024-1876?
To fix CVE-2024-1876, sanitize and validate user input to prevent SQL injection vulnerabilities.
What are the potential consequences of exploiting CVE-2024-1876?
Exploiting CVE-2024-1876 could allow attackers to manipulate the database, extract sensitive information, or disrupt system integrity.
Who is affected by CVE-2024-1876?
CVE-2024-1876 specifically affects users of the SourceCodester Employee Management System version 1.0.