PT-2024-25872 · Sourcecodester · Sourcecodester Prison Management System

Li Yu

·

Published

2024-04-08

·

Updated

2024-05-17

·

CVE-2024-3442

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Prison Management System version 1.0
Description A critical issue has been found in the SourceCodester Prison Management System, affecting the file /Employee/delete leave.php. This issue leads to sql injection and can be initiated remotely. The exploit has been disclosed publicly.
Recommendations For SourceCodester Prison Management System version 1.0, consider restricting access to the /Employee/delete leave.php file until a patch is available. As a temporary workaround, avoid using parameters that may lead to sql injection in this file. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-3442

Affected Products

Sourcecodester Prison Management System