CVE-2024-8564 – SourceCodester PHP CRUD update.php sql injection
https://notcve.org/view.php?id=CVE-2024-8564
A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update.php. The manipulation of the argument tbl_person_id/first_name/middle_name/last_name leads to sql injection. The attack can be initiated remotely. • https://vuldb.com/?ctiid.276784 https://vuldb.com/?id.276784 https://vuldb.com/?submit.403662 https://www.sourcecodester.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-8563 – SourceCodester PHP CRUD update.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-8563
A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/update.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting. It is possible to initiate the attack remotely. • https://vuldb.com/?ctiid.276783 https://vuldb.com/?id.276783 https://vuldb.com/?submit.403661 https://www.sourcecodester.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-8562 – SourceCodester PHP CRUD Add.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-8562
A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /endpoint/Add.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://vuldb.com/?ctiid.276782 https://vuldb.com/?id.276782 https://www.sourcecodester.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-8561 – SourceCodester PHP CRUD Delete Person delete.php sql injection
https://notcve.org/view.php?id=CVE-2024-8561
A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete.php of the component Delete Person Handler. The manipulation of the argument person leads to sql injection. The attack can be launched remotely. In SourceCodester PHP CRUD 1.0 wurde eine Schwachstelle gefunden. • https://vuldb.com/?ctiid.276781 https://vuldb.com/?id.276781 https://vuldb.com/?submit.403651 https://www.sourcecodester.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •