CVE-2024-6043

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects the function login of the file admin_class.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268767.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mayurik:best_house_rental_management_system:1.0:*:*:*:*:*:*:*

History

19 Aug 2024, 17:33

Type Values Removed Values Added
CWE CWE-89

16 Aug 2024, 20:59

Type Values Removed Values Added
References () https://github.com/yezzzo/y3/blob/main/SourceCodester%20Best%20house%20rental%20management%20system%20project%20in%20php%201.0%20SQL%20Injection.md - () https://github.com/yezzzo/y3/blob/main/SourceCodester%20Best%20house%20rental%20management%20system%20project%20in%20php%201.0%20SQL%20Injection.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.268767 - () https://vuldb.com/?ctiid.268767 - Permissions Required, Third Party Advisory
References () https://vuldb.com/?submit.358176 - () https://vuldb.com/?submit.358176 - Third Party Advisory
References () https://vuldb.com/?id.268767 - () https://vuldb.com/?id.268767 - Permissions Required, Third Party Advisory
First Time Mayurik
Mayurik best House Rental Management System
CPE cpe:2.3:a:mayurik:best_house_rental_management_system:1.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

17 Jun 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-17 01:15

Updated : 2024-08-19 17:33


NVD link : CVE-2024-6043

Mitre link : CVE-2024-6043


JSON object : View

Products Affected

mayurik

  • best_house_rental_management_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')