CVE-2024-9818: SourceCodester Online Veterinary Appointment System manage_category.php sql injection
A vulnerability classified as critical has been found in SourceCodester Online Veterinary Appointment System 1.0. Affected is an unknown function of the file /admin/categories/managecategory.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9818?
CVE-2024-9818 is classified as a critical vulnerability.
How does CVE-2024-9818 affect the Online Veterinary Appointment System?
CVE-2024-9818 allows for SQL injection due to improper handling of the 'id' parameter in the manage_category.php file.
What versions are affected by CVE-2024-9818?
CVE-2024-9818 affects version 1.0 of the Online Veterinary Appointment System.
How can I fix CVE-2024-9818?
Fixing CVE-2024-9818 involves sanitizing user input to prevent SQL injection vulnerabilities.
What component of the Online Veterinary Appointment System is vulnerable in CVE-2024-9818?
The vulnerable component in CVE-2024-9818 is the manage_category.php file located in the /admin/categories/ directory.