CVE-2024-40402

A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulnerability stems from insufficient user input validation of the 'username' parameter, allowing attackers to inject malicious SQL queries.
References
Link Resource
https://github.com/CveSecLook/cve/issues/49 Exploit Third Party Advisory
https://github.com/CveSecLook/cve/issues/49 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:nikhil-bhalerao:simple_library_management_system:1.0:*:*:*:*:*:*:*

History

23 Apr 2025, 14:19

Type Values Removed Values Added
References () https://github.com/CveSecLook/cve/issues/49 - () https://github.com/CveSecLook/cve/issues/49 - Exploit, Third Party Advisory
CPE cpe:2.3:a:nikhil-bhalerao:simple_library_management_system:1.0:*:*:*:*:*:*:*
First Time Nikhil-bhalerao
Nikhil-bhalerao simple Library Management System

21 Nov 2024, 09:31

Type Values Removed Values Added
References () https://github.com/CveSecLook/cve/issues/49 - () https://github.com/CveSecLook/cve/issues/49 -

01 Aug 2024, 13:57

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3

18 Jul 2024, 12:28

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad de inyección SQL en 'ajax.php' de Sourcecodester Simple Library Management System 1.0. Esta vulnerabilidad se debe a una validación insuficiente de la entrada del usuario del parámetro 'nombre de usuario', lo que permite a los atacantes inyectar consultas SQL maliciosas.

17 Jul 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-17 20:15

Updated : 2025-04-23 14:19


NVD link : CVE-2024-40402

Mitre link : CVE-2024-40402

CVE.ORG link : CVE-2024-40402


JSON object : View

Products Affected

nikhil-bhalerao

  • simple_library_management_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')