PT-2024-37287 · Sourcecodester · Sourcecodester Employee/Visitor Gate Pass Logging System

Xu Mingming

·

Published

2024-06-13

·

Updated

2024-08-16

·

CVE-2024-5976

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SourceCodester Employee and Visitor Gate Pass Logging System version 1.0
Description: A critical issue was found in the log employee function of the /classes/Master.php file, where the manipulation of the employee code argument leads to SQL injection. This issue can be exploited remotely.
Recommendations: For version 1.0, consider disabling the log employee function until a patch is available to prevent SQL injection attacks. Restrict access to the /classes/Master.php file to minimize the risk of exploitation. Avoid using the employee code argument in the affected function until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-5976

Affected Products

Sourcecodester Employee/Visitor Gate Pass Logging System