CVE-2024-9974: SourceCodester Online Eyewear Shop POST Request Master.php sql injection
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file classes/Master.php?f=addtocard of the component POST Request Handler. The manipulation of the argument productid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9974?
CVE-2024-9974 has been declared as a critical vulnerability.
How do I fix CVE-2024-9974?
To fix CVE-2024-9974, update to the latest version of SourceCodester Online Eyewear Shop if one is available.
What component is affected by CVE-2024-9974?
CVE-2024-9974 affects the POST Request Handler in the classes/Master.php file.
What kind of attack could exploit CVE-2024-9974?
CVE-2024-9974 could potentially allow unauthorized manipulation of the argument in the application.
Is my software vulnerable if I am using SourceCodester Online Eyewear Shop 1.0?
Yes, if you are using SourceCodester Online Eyewear Shop 1.0, you are potentially vulnerable to CVE-2024-9974.