PT-2024-20293 · Unknown · Sourcecodester School Task Manager

Buraksevben

·

Published

2024-01-29

·

Updated

2024-08-23

·

CVE-2024-24141

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester School Task Manager App version 1.0
Description The issue allows SQL Injection via the task parameter. This could potentially be exploited to extract or modify sensitive data. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For Sourcecodester School Task Manager App version 1.0, avoid using the task parameter in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-24141

Affected Products

Sourcecodester School Task Manager