PT-2024-33107 · Unknown · Sourcecodester Packers/Movers Management System

Oretnom23

·

Published

2024-10-24

·

Updated

2024-10-31

·

CVE-2024-48427

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Packers and Movers Management System version 1.0
Description A SQL injection issue allows remote authenticated users to execute arbitrary SQL commands via the id parameter in the "/mpms/admin/?page=services/manage service&id" API endpoint.
Recommendations For Sourcecodester Packers and Movers Management System version 1.0, consider restricting access to the /mpms/admin/?page=services/manage service&id API endpoint until a patch is available. As a temporary workaround, avoid using the id parameter in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-48427

Affected Products

Sourcecodester Packers/Movers Management System