PT-2024-37287 · Sourcecodester · Sourcecodester Employee/Visitor Gate Pass Logging System
Xu Mingming
·
Published
2024-06-13
·
Updated
2024-08-16
·
CVE-2024-5976
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
SourceCodester Employee and Visitor Gate Pass Logging System version 1.0
Description:
A critical issue was found in the log employee function of the /classes/Master.php file, where the manipulation of the
employee code argument leads to SQL injection. This issue can be exploited remotely.Recommendations:
For version 1.0, consider disabling the
log employee function until a patch is available to prevent SQL injection attacks. Restrict access to the /classes/Master.php file to minimize the risk of exploitation. Avoid using the employee code argument in the affected function until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Employee/Visitor Gate Pass Logging System