CVE-2024-2932: SourceCodester Online Chatting System update_room.php sql injection
Published Mar 27, 2024
·Updated
A vulnerability classified as critical has been found in SourceCodester Online Chatting System 1.0. Affected is an unknown function of the file admin/updateroom.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258012.
Affected Software
2 affected components
Donbermoy Online Chatting System=1.0
Sourcecodester Online Chatting System
Event History
Mar 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Jan 25, 57107
Event
via NVD·08:35 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-2932?
CVE-2024-2932 is classified as a critical vulnerability.
2
What is the nature of the vulnerability in CVE-2024-2932?
The vulnerability in CVE-2024-2932 is an SQL injection found in the admin/update_room.php file.
3
How can I fix CVE-2024-2932?
To fix CVE-2024-2932, validate and sanitize all inputs to the update_room.php function.
4
What software is affected by CVE-2024-2932?
CVE-2024-2932 affects SourceCodester Online Chatting System version 1.0.
5
Can CVE-2024-2932 be exploited remotely?
Yes, CVE-2024-2932 can be exploited remotely.