A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-computer.php. The manipulation of the argument computer leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-255382 is the identifier assigned to this vulnerability.
References
Link | Resource |
---|---|
https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20Computer%20Inventory%20System%20Using%20PHP/SQL%20Injection%20delete-computer.php%20.md | Broken Link |
https://vuldb.com/?ctiid.255382 | Permissions Required |
https://vuldb.com/?id.255382 | Third Party Advisory |
https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20Computer%20Inventory%20System%20Using%20PHP/SQL%20Injection%20delete-computer.php%20.md | Broken Link |
https://vuldb.com/?ctiid.255382 | Permissions Required |
https://vuldb.com/?id.255382 | Third Party Advisory |
Configurations
History
17 Dec 2024, 22:01
Type | Values Removed | Values Added |
---|---|---|
First Time |
Remyandrade computer Inventory System
Remyandrade |
|
CPE | cpe:2.3:a:remyandrade:computer_inventory_system:1.0:*:*:*:*:*:*:* | |
References | () https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20Computer%20Inventory%20System%20Using%20PHP/SQL%20Injection%20delete-computer.php%20.md - Broken Link | |
References | () https://vuldb.com/?ctiid.255382 - Permissions Required | |
References | () https://vuldb.com/?id.255382 - Third Party Advisory |
21 Nov 2024, 09:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/skid-nochizplz/skid-nochizplz/blob/main/TrashBin/CVE/SOURCECODESTER%20Computer%20Inventory%20System%20Using%20PHP/SQL%20Injection%20delete-computer.php%20.md - | |
References | () https://vuldb.com/?ctiid.255382 - | |
References | () https://vuldb.com/?id.255382 - |
21 Mar 2024, 02:52
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
01 Mar 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-01 15:15
Updated : 2024-12-17 22:01
NVD link : CVE-2024-2067
Mitre link : CVE-2024-2067
CVE.ORG link : CVE-2024-2067
JSON object : View
Products Affected
remyandrade
- computer_inventory_system
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')