SourceCodester Employee Task Management System task-details.php sql injection

CVE Details

Basic Information

Title SourceCodester Employee Task Management System task-details.php sql injection
Type cve
Published 2023-02-18T07:37:20.668Z
Modified 2024-08-02T05:24:34.782Z

Product Information

Vendor SourceCodester
Product Employee Task Management System
Version 1.0

CVSS Information

Base Score 6.3 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Analysis

AI Description A SQL injection vulnerability exists in the task-details.php file of SourceCodester Employee Task Management System 1.0. This allows remote attackers to inject malicious SQL code via the task_id argument, potentially leading to unauthorized data access or modification.
AI Severity Medium
AI Vendor SourceCodester
AI Product Employee Task Management System
AI Version 1.0

Affected Products

  • SourceCodester Employee Task Management System 1.0

Additional Information

CWE List CWE-89
Source VulDB

Description

A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file task-details.php. The manipulation of the argument task_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221453 was assigned to this vulnerability.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.