CVE-2024-3439
Last modified
CVE-2024-3439 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was found in SourceCodester Prison Management System 1.0. It has been classified as critical. EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
A vulnerability was found in SourceCodester Prison Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Account/login.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259692.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fast5 | Prison Management System | 1.0 |
References
- https://github.com/fubxx/CVE/blob/main/PrisonManagementSystemSQL2.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.259692Permissions Required, VDB Entry
- https://vuldb.com/?id.259692Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.312204Third Party Advisory, VDB Entry
- https://github.com/fubxx/CVE/blob/main/PrisonManagementSystemSQL2.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.259692Permissions Required, VDB Entry
- https://vuldb.com/?id.259692Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.312204Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-3439?
How severe is CVE-2024-3439?
How do I fix CVE-2024-3439?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-34384Improper Limitation of a Pathname to a Restricted Directory …8.8
- CVE-2024-34385Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2024-34386Improper Neutralization of Special Elements used in an SQL C…7.6
- CVE-2024-34387Missing Authorization vulnerability in AF themes WP Post Aut…4.3
- CVE-2024-34388Exposure of Sensitive Information to an Unauthorized Actor v…7.5
- CVE-2024-34389Missing Authorization vulnerability in AF themes WP Post Aut…4.3
- CVE-2024-34390Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-34391libxmljs is vulnerable to a type confusion vulnerability whe…9.8
- CVE-2024-34392libxmljs is vulnerable to a type confusion vulnerability whe…9.8
- CVE-2024-34393libxmljs2 is vulnerable to a type confusion vulnerability wh…8.1
- CVE-2024-34394libxmljs2 is vulnerable to a type confusion vulnerability wh…8.1
- CVE-2024-34397An issue was discovered in GNOME GLib before 2.78.5, and 2.7…5.2
Are you affected by CVE-2024-3439?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
