CVE-2024-3359: SourceCodester Online Library System login.php sql injection
A vulnerability, which was classified as critical, has been found in SourceCodester Online Library System 1.0. This issue affects some unknown processing of the file admin/login.php. The manipulation of the argument useremail leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259463.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3359?
CVE-2024-3359 is classified as a critical vulnerability.
How does CVE-2024-3359 affect the Online Library System?
CVE-2024-3359 allows for SQL injection through the manipulation of the user_email argument in admin/login.php.
How do I fix CVE-2024-3359?
To fix CVE-2024-3359, it's recommended to validate and sanitize input data in the admin/login.php file to prevent SQL injection.
Is CVE-2024-3359 remotely exploitable?
Yes, CVE-2024-3359 can be remotely exploited by attackers.
Which versions of the Online Library System are affected by CVE-2024-3359?
CVE-2024-3359 affects SourceCodester Online Library System version 1.0.