PT-2024-38475 · Sourcecodester · Sourcecodester Leads Manager Tool

Joinia

·

Published

2024-08-09

·

Updated

2024-08-15

·

CVE-2024-7643

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Leads Manager Tool version 1.0
Description A critical issue was found in the Delete Leads Handler component, specifically in the file /endpoint/delete-leads.php. The leads argument is vulnerable to SQL injection, which can be exploited remotely. The issue affects some unknown functionality of the file.
Recommendations For SourceCodester Leads Manager Tool version 1.0, as a temporary workaround, consider restricting access to the /endpoint/delete-leads.php endpoint until a patch is available. Avoid using the leads argument in the affected endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-7643

Affected Products

Sourcecodester Leads Manager Tool