PT-2024-20998 · Sourcecodester · Sourcecodester Employee Task Management System

Peanut

·

Published

2024-03-16

·

Updated

2024-05-17

·

CVE-2024-2555

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Employee Task Management System version 1.0
Description A critical issue was found in the SourceCodester Employee Task Management System, affecting some unknown functionality of the file update-admin.php. The manipulation of the admin id argument leads to SQL injection. The attack can be launched remotely.
Recommendations For SourceCodester Employee Task Management System version 1.0, consider disabling the admin id argument in the update-admin.php file as a temporary workaround until a patch is available. Restrict access to the update-admin.php file to minimize the risk of exploitation. Avoid using the admin id argument in the affected functionality until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-2555

Affected Products

Sourcecodester Employee Task Management System