CVE-2024-3360 – SourceCodester Online Library System index.php sql injection
https://notcve.org/view.php?id=CVE-2024-3360
A vulnerability, which was classified as critical, was found in SourceCodester Online Library System 1.0. Affected is an unknown function of the file admin/books/index.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/thisissuperann/Vul/blob/main/Online-Library-System-02 https://vuldb.com/?ctiid.259464 https://vuldb.com/?id.259464 https://vuldb.com/?submit.310424 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-3359 – SourceCodester Online Library System login.php sql injection
https://notcve.org/view.php?id=CVE-2024-3359
A vulnerability, which was classified as critical, has been found in SourceCodester Online Library System 1.0. This issue affects some unknown processing of the file admin/login.php. The manipulation of the argument user_email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/thisissuperann/Vul/blob/main/Online-Library-System-01 https://vuldb.com/?ctiid.259463 https://vuldb.com/?id.259463 https://vuldb.com/?submit.310423 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •