CVE-2024-5094
Mayurik
CVE-2024-5094: Critical SQL injection vulnerability discovered in SourceCodester Best House Rental Management System 1.0. Remote attackers can exploit this flaw in view_payment.php by manipulating the 'id' argument, potentially leading to unauthorized database access. While the CVSS score is a high 9.8, SOCRadar's Vulnerability Risk Score (SVRS) is 30, suggesting a lower immediate risk compared to vulnerabilities with SVRS scores above 80, however the presence of a public exploit marked as "In The Wild" is a serious threat. Successful exploitation could allow attackers to read, modify, or delete sensitive data, potentially compromising the entire rental management system. Immediate patching is still highly recommended to prevent potential attacks, despite the SVRS score not being critical. This type of SQL injection vulnerability is common and well-understood, making it easier for attackers to exploit.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.