CVE-2024-5515: SourceCodester Stock Management System createBrand.php sql injection
A vulnerability was found in SourceCodester Stock Management System 1.0. It has been classified as critical. Affected is an unknown function of the file createBrand.php. The manipulation of the argument brandName leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-266586 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5515?
CVE-2024-5515 has been classified as critical due to its potential for remote SQL injection.
How does CVE-2024-5515 affect the SourceCodester Stock Management System?
CVE-2024-5515 affects the createBrand.php file by allowing SQL injection through the brandName argument.
Can CVE-2024-5515 be exploited remotely?
Yes, CVE-2024-5515 can be exploited remotely, making it particularly dangerous.
How do I fix CVE-2024-5515?
To mitigate CVE-2024-5515, sanitize and validate all user inputs in the affected functions before processing.
Which version of the Stock Management System is affected by CVE-2024-5515?
CVE-2024-5515 affects SourceCodester Stock Management System version 1.0.