CVE-2024-3416
Last modified
CVE-2024-3416 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability classified as critical was found in SourceCodester Online Courseware 1.0. This vulnerability affects unknown code of the file admin/editt.php. EPSS estimates a 0.94% chance of exploitation in the next 30 days.
Description
A vulnerability classified as critical was found in SourceCodester Online Courseware 1.0. This vulnerability affects unknown code of the file admin/editt.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259588.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Argie | Online Courseware | 1.0 |
References
- https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-01.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.259588Permissions Required
- https://vuldb.com/?id.259588Permissions Required, Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.311593Third Party Advisory, VDB Entry
- https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-01.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.259588Permissions Required
- https://vuldb.com/?id.259588Permissions Required, Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.311593Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-3416?
How severe is CVE-2024-3416?
How do I fix CVE-2024-3416?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-34153Uncontrolled search path element in Intel(R) RAID Web Consol…7.8
- CVE-2024-34154Rejected reason: reserved but not needed
- CVE-2024-34155Calling any of the Parse functions on Go source code which c…4.3
- CVE-2024-34156Calling Decoder.Decode on a message which contains deeply ne…7.5
- CVE-2024-34157Rejected reason: reserved but not needed
- CVE-2024-34158Calling Parse on a "// +build" build tag line with deeply ne…7.5
- CVE-2024-34161When NGINX Plus or NGINX OSS are configured to use the HTTP/…5.3
- CVE-2024-34162The web interface of the affected devices is designed to hid…5.3
- CVE-2024-34163Improper input validation in firmware for some Intel(R) NUC …8.2
- CVE-2024-34164Uncontrolled search path element in some Intel(R) MAS softwa…6.7
- CVE-2024-34165Uncontrolled search path in some Intel(R) oneAPI DPC++/C++ C…6.7
- CVE-2024-34166An os command injection vulnerability exists in the touchlis…9.8
Are you affected by CVE-2024-3416?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
