CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-5384

High Severity
SVRS
68/100

CVSSv3
7.3/10

EPSS
0.00029/1

CVE-2024-5384 exposes a critical SQL Injection vulnerability in SourceCodester Facebook News Feed Like 1.0. Attackers can remotely manipulate the 'page' argument in index.php to inject malicious SQL code. While its CVSS score is 7.3, the SOCRadar Vulnerability Risk Score (SVRS) is 68. This means while serious, it's below the threshold requiring immediate action. Successful exploitation could allow unauthorized database access, potentially leading to data theft or system compromise. Given the remote attack vector and the potential for data breach, organizations using this software should investigate and patch this vulnerability promptly to mitigate risk. Though not immediately critical based on SVRS, proactive security measures are advised.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:N
UI:N
S:U
C:L
I:L
A:L
2024-05-27

2024-06-04

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-5384 | SourceCodester Facebook News Feed Like 1.0 index.php page sql injection
vuldb.com2024-05-25
CVE-2024-5384 | SourceCodester Facebook News Feed Like 1.0 index.php page sql injection | A vulnerability classified as critical was found in SourceCodester Facebook News Feed Like 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument page leads to sql injection. This vulnerability was named CVE-2024-5384. The attack can be initiated
vuldb.com
rss
forum
news

Social Media

🚨 CVE-2024-5384: Critical SQL injection in SourceCodester Facebook News Feed Like 1.0's index.php. Attacker can remotely exploit to access sensitive data. Patch immediately & validate inputs. #SQLi #InfoSec
0
0
0
CVE-2024-5384 A vulnerability classified as critical was found in SourceCodester Facebook News Feed Like 1.0. This vulnerability affects unknown code of the file index.php. The manip… https://t.co/KnKTrOGtTG
0
0
0
A new vulnerability with increased severity was disclosed for SourceCodester Facebook News Feed Like (CVE-2024-5384) https://t.co/YOPTXUFnzL
0
0
0

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://vuldb.com/?ctiid.266302
[email protected]https://vuldb.com/?id.266302
[email protected]https://vuldb.com/?submit.344502
GITHUBhttps://vuldb.com/?id.266302

CWE Details

CWE IDCWE NameDescription
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence