First published: Wed Jun 12 2024(Updated: )
A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is the function save_users of the file /classes/Users.php?f=save. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268140.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Employee and Visitor Gate Pass Logging System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5896 is classified as a critical vulnerability due to its potential for SQL injection.
To fix CVE-2024-5896, it is recommended to sanitize user inputs and implement prepared statements in the save_users function.
CVE-2024-5896 affects version 1.0 of the SourceCodester Employee and Visitor Gate Pass Logging System.
CVE-2024-5896 allows attackers to perform SQL injection through the manipulation of the argument id.
The vulnerability in CVE-2024-5896 is located in the save_users function of the file /classes/Users.php.