CVE-2024-4798: SourceCodester Online Computer and Laptop Store manage_brand.php sql injection
A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file /admin/maintenance/managebrand.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263918 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4798?
CVE-2024-4798 is classified as a critical vulnerability.
How does CVE-2024-4798 manifest in the software?
CVE-2024-4798 manifests through SQL injection via the id argument in the file /admin/maintenance/manage_brand.php.
What software is affected by CVE-2024-4798?
CVE-2024-4798 affects version 1.0 of SourceCodester Online Computer and Laptop Store.
How can CVE-2024-4798 be mitigated?
To mitigate CVE-2024-4798, sanitize user inputs used in SQL queries and implement prepared statements.
Is there a patch available for CVE-2024-4798?
Currently, there is no specific patch information available for CVE-2024-4798.