PT-2024-30021 · Unknown · Pharmacy Management System

Topsky979

·

Published

2024-08-20

·

Updated

2024-08-20

·

CVE-2024-42561

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pharmacy Management System version a2efc8
Description The issue is related to a SQL injection vulnerability. This vulnerability can be exploited via the invoice number parameter at the "sales report.php" endpoint.
Recommendations For version a2efc8, consider restricting access to the "sales report.php" endpoint until a patch is available. As a temporary workaround, avoid using the invoice number parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-42561

Affected Products

Pharmacy Management System