CVE-2024-5976: SourceCodester Employee and Visitor Gate Pass Logging System log_employee sql injection
A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been classified as critical. Affected is the function logemployee of the file /classes/Master.php?f=logemployee. The manipulation of the argument employeecode leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-268422 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5976?
CVE-2024-5976 has been classified as critical due to the risk of SQL injection vulnerabilities.
How do I fix CVE-2024-5976?
To fix CVE-2024-5976, ensure input validation and parameterized queries are implemented in the log_employee function of the Master.php file.
What systems are affected by CVE-2024-5976?
CVE-2024-5976 affects SourceCodester Employee and Visitor Gate Pass Logging System version 1.0.
What kind of attack can be executed through CVE-2024-5976?
CVE-2024-5976 allows attackers to conduct SQL injection attacks through the employee_code parameter.
Is CVE-2024-5976 actively exploited in the wild?
As of now, there are no confirmed reports indicating that CVE-2024-5976 is actively exploited in the wild.