Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Huang Yue

#14229of 53,633
18.9Total CVSS
Vulnerabilities · 2
Critical
2
PT-2024-27116
9.8
2024-06-07
Unknown · Sourcecodester Pharmacy/Medical Store Point Of Sale System · CVE-2024-36673
**Name of the Vulnerable Software and Affected Versions** Sourcecodester Pharmacy/Medical Store Point of Sale System version 1.0 **Description** The issue stems from inadequate validation of user inputs for the `email` and `password` parameters in the "login.php" endpoint, allowing attackers to inject malicious SQL queries. **Recommendations** For Sourcecodester Pharmacy/Medical Store Point of Sale System version 1.0, consider disabling the login functionality via "login.php" until a patch is available, and restrict access to the `email` and `password` parameters to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-25190
9.1
2024-05-06
Unknown · Library System · CVE-2024-33294
**Name of the Vulnerable Software and Affected Versions** Library System version V1.0 **Description** An issue in the Library System allows a remote attacker to execute arbitrary code via the ` FAILE` variable in the `student edit photo.php` component. **Recommendations** For Library System version V1.0, consider disabling access to the `student edit photo.php` component until a patch is available to prevent exploitation via the ` FAILE` variable.