PoC Index

CVE-2024-40402

MEDIUM 6.3EPSS 0.4%

A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulnerability stems from insufficient user input validation of the 'username' parameter, allowing attackers to inject malicious SQL queries.

CVSS v3.1
6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS
0.37% chance of exploitation in the next 30 days, 30th percentile
Published
2024-07-17
Updated
2024-08-02

Proof-of-concept exploits (1)

References

Related