CVE-2024-51030

A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, leading to unauthorized access and potential compromise of sensitive data within the database.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oretnom23:cab_management_system:1.0:*:*:*:*:*:*:*

History

13 Nov 2024, 16:47

Type Values Removed Values Added
References () https://github.com/vighneshnair7/CVE-2024-51030 - () https://github.com/vighneshnair7/CVE-2024-51030 - Third Party Advisory
References () https://www.sourcecodester.com/php/15180/cab-management-system-phpoop-free-source-code.html - () https://www.sourcecodester.com/php/15180/cab-management-system-phpoop-free-source-code.html - Product
CWE CWE-89
First Time Oretnom23
Oretnom23 cab Management System
Summary
  • (es) Una vulnerabilidad de inyección SQL en manage_client.php y view_cab.php de Sourcecodester Cab Management System 1.0 permite a atacantes remotos ejecutar comandos SQL arbitrarios a través del parámetro id, lo que lleva a un acceso no autorizado y a un posible compromiso de datos confidenciales dentro de la base de datos.
CPE cpe:2.3:a:oretnom23:cab_management_system:1.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

08 Nov 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-08 18:15

Updated : 2024-11-21 17:15


NVD link : CVE-2024-51030

Mitre link : CVE-2024-51030

CVE.ORG link : CVE-2024-51030


JSON object : View

Products Affected

oretnom23

  • cab_management_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')