CVE-2024-3361: SourceCodester Online Library System deweydecimal.php sql injection
A vulnerability has been found in SourceCodester Online Library System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/books/deweydecimal.php. The manipulation of the argument category leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259465 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3361?
CVE-2024-3361 is classified as a critical vulnerability.
How does CVE-2024-3361 manifest in the SourceCodester Online Library System?
CVE-2024-3361 manifests through SQL injection due to manipulation of the argument 'category' in the admin/books/deweydecimal.php file.
What software is affected by CVE-2024-3361?
CVE-2024-3361 affects SourceCodester Online Library System version 1.0.
How can I mitigate CVE-2024-3361?
To mitigate CVE-2024-3361, ensure that proper input validation and parameterized queries are implemented to prevent SQL injection.
What actions can be taken if CVE-2024-3361 is exploited?
If CVE-2024-3361 is exploited, immediate steps should be taken to patch the vulnerability and further investigate any unauthorized access or data breaches.