CVE-2024-36673
Pharmacy\/medical_store_point_of_sale_system_project
CVE-2024-36673: Critical SQL Injection vulnerability in Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 via login.php. Attackers can exploit this vulnerability by injecting malicious SQL queries through the email and password parameters due to insufficient input validation. With a SOCRadar Vulnerability Risk Score (SVRS) of 84, this vulnerability requires immediate action. Successful exploitation could lead to unauthorized data access, modification, or even complete system compromise. This vulnerability is especially critical for systems directly handling sensitive patient or financial information. The high SVRS indicates active exploitation or discussions within threat actor communities, making prompt patching or mitigation essential to prevent significant security breaches.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.