First published: Sat Apr 06 2024(Updated: )
A vulnerability has been found in SourceCodester Online Library System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/books/deweydecimal.php. The manipulation of the argument category leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259465 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Online Library System | ||
Janobe Online Library System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3361 is classified as a critical vulnerability.
CVE-2024-3361 manifests through SQL injection due to manipulation of the argument 'category' in the admin/books/deweydecimal.php file.
CVE-2024-3361 affects SourceCodester Online Library System version 1.0.
To mitigate CVE-2024-3361, ensure that proper input validation and parameterized queries are implemented to prevent SQL injection.
If CVE-2024-3361 is exploited, immediate steps should be taken to patch the vulnerability and further investigate any unauthorized access or data breaches.