CVE-2024-6419: SourceCodester Medicine Tracker System sql injection
A vulnerability classified as critical was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affects unknown code of the file /classes/Master.php?f=savemedicine. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-270010 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6419?
CVE-2024-6419 is classified as critical due to its potential for remote SQL injection.
How do I fix CVE-2024-6419?
To fix CVE-2024-6419, update to the latest version of the Medicine Tracker System that addresses the SQL injection vulnerability.
What kind of attack does CVE-2024-6419 allow?
CVE-2024-6419 allows for remote exploitation through SQL injection, which can manipulate database queries.
Which software versions are affected by CVE-2024-6419?
CVE-2024-6419 affects version 1.0 of the Medicine Tracker System by Oretnom23.
Where in the software is CVE-2024-6419 located?
CVE-2024-6419 is located in the file /classes/Master.php?f=save_medicine within the Medicine Tracker System.