CVE-2024-9319: SourceCodester Online Timesheet App delete-timesheet.php sql injection
A vulnerability, which was classified as critical, was found in SourceCodester Online Timesheet App 1.0. This affects an unknown part of the file /endpoint/delete-timesheet.php. The manipulation of the argument timesheet leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9319?
CVE-2024-9319 is classified as a critical vulnerability due to its potential for SQL injection.
How do I fix CVE-2024-9319?
To fix CVE-2024-9319, update the SourceCodester Online Timesheet App to the latest version or implement input validation to prevent SQL injection.
What systems are affected by CVE-2024-9319?
CVE-2024-9319 affects SourceCodester Online Timesheet App version 1.0.
Can CVE-2024-9319 be exploited remotely?
Yes, CVE-2024-9319 can be exploited remotely through the vulnerable delete-timesheet.php endpoint.
What type of attacks can CVE-2024-9319 lead to?
CVE-2024-9319 can lead to SQL injection attacks, potentially compromising database security.