CVE-2024-2554: SourceCodester Employee Task Management System update-employee.php sql injection
A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file update-employee.php. The manipulation of the argument adminid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257053 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2554?
The severity of CVE-2024-2554 is classified as critical.
What type of vulnerability is CVE-2024-2554?
CVE-2024-2554 is a SQL injection vulnerability found in the update-employee.php file.
Which software is affected by CVE-2024-2554?
CVE-2024-2554 affects SourceCodester Employee Task Management System version 1.0.
How do I fix CVE-2024-2554?
To fix CVE-2024-2554, sanitize and validate inputs for the admin_id parameter in the update-employee.php file.
What impact does CVE-2024-2554 have?
CVE-2024-2554 can allow attackers to execute arbitrary SQL commands, potentially compromising the database.