Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Josué Mier

#25478of 53,633
9.8Total CVSS
Vulnerabilities · 1
PT-2024-20840
9.8
2024-02-29
Unknown · Sourcecodester Employee Management System · CVE-2024-25239
**Name of the Vulnerable Software and Affected Versions** Sourcecodester Employee Management System version 1.0 **Description** The issue allows attackers to execute arbitrary SQL commands through a crafted POST request to the "/emloyee akpoly/Account/login.php" API endpoint. This enables attackers to manipulate the database, potentially leading to unauthorized data access or modification. **Recommendations** For Sourcecodester Employee Management System version 1.0, consider restricting access to the "/emloyee akpoly/Account/login.php" API endpoint until a patch is available. As a temporary workaround, avoid using user-input data directly in SQL queries to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.