CVE-2024-40402
MEDIUM 6.3EPSS 0.4%
A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulnerability stems from insufficient user input validation of the 'username' parameter, allowing attackers to inject malicious SQL queries.
- CVSS v3.1
- 6.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L - EPSS
- 0.37% chance of exploitation in the next 30 days, 30th percentile
- Published
- 2024-07-17
- Updated
- 2024-08-02