Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerability stems from inadequate validation of user inputs for the email and password parameters, allowing attackers to inject malicious SQL queries.
References
Link | Resource |
---|---|
https://github.com/CveSecLook/cve/issues/39 | Exploit Issue Tracking Third Party Advisory |
https://github.com/CveSecLook/cve/issues/39 | Exploit Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 09:22
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/CveSecLook/cve/issues/39 - Exploit, Issue Tracking, Third Party Advisory |
11 Jun 2024, 18:27
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-89 | |
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | () https://github.com/CveSecLook/cve/issues/39 - Exploit, Issue Tracking, Third Party Advisory | |
CPE | cpe:2.3:a:pharmacy\/medical_store_point_of_sale_system_project:pharmacy\/medical_store_point_of_sale_system:1.0:*:*:*:*:*:*:* | |
First Time |
Pharmacy\/medical Store Point Of Sale System Project
Pharmacy\/medical Store Point Of Sale System Project pharmacy\/medical Store Point Of Sale System |
07 Jun 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-07 13:15
Updated : 2024-11-21 09:22
NVD link : CVE-2024-36673
Mitre link : CVE-2024-36673
CVE.ORG link : CVE-2024-36673
JSON object : View
Products Affected
pharmacy\/medical_store_point_of_sale_system_project
- pharmacy\/medical_store_point_of_sale_system
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')