PoC Index

CVE-2024-36673

CRITICAL 9.8EPSS 0.5%

Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerability stems from inadequate validation of user inputs for the email and password parameters, allowing attackers to inject malicious SQL queries.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.52% chance of exploitation in the next 30 days, 42th percentile
Published
2024-06-07
Updated
2025-02-13

Proof-of-concept exploits (1)

References

Related