First published: Wed Jun 12 2024(Updated: )
A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects the function delete_users of the file /classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268139.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Employee and Visitor Gate Pass Logging System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5895 is classified as a critical vulnerability.
CVE-2024-5895 exploits the system through SQL injection via the delete_users function in the Users.php file.
CVE-2024-5895 affects SourceCodester Employee and Visitor Gate Pass Logging System version 1.0.
To fix CVE-2024-5895, sanitize user inputs and implement proper prepared statements to prevent SQL injection.
If CVE-2024-5895 is not addressed, attackers could exploit the vulnerability to gain unauthorized access to the database.