CVE-2024-25214: SQL Injection
An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25214?
CVE-2024-25214 is considered a critical vulnerability due to its potential to allow unauthorized access to the Employee Management System.
How do I fix CVE-2024-25214?
To fix CVE-2024-25214, update the Employee Management System to a secure version that addresses this authentication bypass issue.
What software is affected by CVE-2024-25214?
CVE-2024-25214 affects version 1.0 of the Employee Management System developed by Sherlock.
What kind of attack is associated with CVE-2024-25214?
CVE-2024-25214 involves an authentication bypass attack via crafted payloads injected into E-mail and Password parameters.
Where does the vulnerability CVE-2024-25214 occur in the application?
The vulnerability CVE-2024-25214 occurs at the /alogin.html endpoint of the Employee Management System.