First published: Tue Oct 15 2024(Updated: )
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=reports of the component Report Viewing Page. The manipulation of the argument date leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Online Eyewear Shop | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9973 has been classified as critical.
CVE-2024-9973 affects the Report Viewing Page function in the SourceCodester Online Eyewear Shop version 1.0.
CVE-2024-9973 allows for SQL injection through manipulation of the 'date' argument in the affected function.
To fix CVE-2024-9973, validate and sanitize all user inputs in the affected function to prevent SQL injection.
CVE-2024-9973 can lead to unauthorized access and manipulation of the database, resulting in data breaches.