First published: Tue Oct 15 2024(Updated: )
A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_customer.php?action=search. The manipulation of the argument text leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
code-projects Pharmacy Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9976 is classified as a critical vulnerability due to its potential for SQL injection.
To fix CVE-2024-9976, ensure proper input validation and use prepared statements to prevent SQL injection.
CVE-2024-9976 affects the manage_customer.php file in the Pharmacy Management System version 1.0.
CVE-2024-9976 is a SQL injection vulnerability that allows attackers to manipulate database queries.
Yes, CVE-2024-9976 can be exploited remotely if the attacker has access to the affected system's search functionality.