CVE-2024-36779: SQL Injection
Published Jun 6, 2024
·Updated
Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.
Affected Software
1 affected component
Stock Management System Project Stock Management System=1.0
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
Jun 6, 2024
CVE Published
via NVD·01:15 PM
Aug 20, 2024
Data Sourced
via MITRE·03:30 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-36779?
CVE-2024-36779 has been classified as a medium severity vulnerability due to its potential for unauthorized database access.
2
How do I fix CVE-2024-36779?
To fix CVE-2024-36779, implement input validation and use prepared statements to prevent SQL injection in the editCategories.php file.
3
Which version of Stock Management System is affected by CVE-2024-36779?
CVE-2024-36779 affects version 1.0 of the Stock Management System.
4
What type of attack does CVE-2024-36779 facilitate?
CVE-2024-36779 facilitates SQL injection attacks that can lead to unauthorized data manipulation.
5
Is the Stock Management System vulnerable in its default configuration due to CVE-2024-36779?
Yes, the Stock Management System is vulnerable in its default configuration, allowing SQL injection through the editCategories.php file.