PT-2024-38793 · Unknown · Sourcecodester Online Computer/Laptop Store

Fany

·

Published

2024-08-22

·

Updated

2024-08-27

·

CVE-2024-8083

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SourceCodester Online Computer and Laptop Store version 1.0
Description: A critical issue has been found in the software, affecting an unknown functionality of the file /php-ocls/classes/Master.php?f=pay order. The manipulation of the id argument leads to SQL injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. An attacker can manipulate the id in Master.php for unauthorized access.
Recommendations: For SourceCodester Online Computer and Laptop Store version 1.0, patch immediately and validate user input to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the vulnerable functionality of the file /php-ocls/classes/Master.php?f=pay order until a patch is available. Avoid using the id argument in the affected file until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-8083

Affected Products

Sourcecodester Online Computer/Laptop Store