PT-2024-38556 · Sourcecodester · Sourcecodester Accounts Manager App

Joinia

·

Published

2024-08-13

·

Updated

2024-11-22

·

CVE-2024-7748

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Accounts Manager App version 1.0
Description A critical issue has been found in the processing of the file "/endpoint/delete-account.php". The manipulation of the account argument leads to SQL injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. An attacker can delete accounts via the vulnerable "delete-account.php" endpoint.
Recommendations For SourceCodester Accounts Manager App version 1.0, patch immediately to prevent exploitation. Additionally, check logs for signs of exploit. As a temporary workaround, consider restricting access to the "/endpoint/delete-account.php" endpoint until a patch is available. Avoid using the account argument in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-7748

Affected Products

Sourcecodester Accounts Manager App