PT-2024-27116 · Unknown · Sourcecodester Pharmacy/Medical Store Point Of Sale System

Huang Yue

·

Published

2024-06-07

·

Updated

2024-08-16

·

CVE-2024-36673

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Pharmacy/Medical Store Point of Sale System version 1.0
Description The issue stems from inadequate validation of user inputs for the email and password parameters in the "login.php" endpoint, allowing attackers to inject malicious SQL queries.
Recommendations For Sourcecodester Pharmacy/Medical Store Point of Sale System version 1.0, consider disabling the login functionality via "login.php" until a patch is available, and restrict access to the email and password parameters to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-36673

Affected Products

Sourcecodester Pharmacy/Medical Store Point Of Sale System