CVE-2024-8086: SourceCodester E-Commerce System Admin Login login.php sql injection
A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ecommerce/admin/login.php of the component Admin Login. The manipulation of the argument useremail leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8086?
CVE-2024-8086 is classified as a critical severity vulnerability.
What component is affected by CVE-2024-8086?
CVE-2024-8086 affects the Admin Login component of SourceCodester E-Commerce System version 1.0.
What type of vulnerability is CVE-2024-8086?
CVE-2024-8086 is a SQL injection vulnerability.
How do I fix CVE-2024-8086?
To fix CVE-2024-8086, ensure that input validation and sanitization are implemented for the user_email parameter in the admin login script.
What versions of SourceCodester E-Commerce System are affected by CVE-2024-8086?
CVE-2024-8086 affects SourceCodester E-Commerce System version 1.0.