PT-2024-22864 · Sourcecodester · Sourcecodester Todo List In Kanban Board

Burak

·

Published

2024-03-26

·

Updated

2024-05-17

·

CVE-2024-2934

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Todo List in Kanban Board version 1.0
Description A critical issue was found in the software, affecting an unknown functionality of the file "/endpoint/delete-todo.php". The manipulation of the list argument leads to SQL injection. The attack can be launched remotely.
Recommendations For version 1.0, consider disabling the "/endpoint/delete-todo.php" endpoint until a patch is available to prevent SQL injection attacks. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using the list argument in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-2934

Affected Products

Sourcecodester Todo List In Kanban Board