{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-3464","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2024-04-08T12:32:47.258Z","datePublished":"2024-04-08T20:00:05.612Z","dateUpdated":"2024-08-01T20:12:07.865Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-04-08T20:00:05.612Z"},"title":"SourceCodester Laundry Management System Pelanggan.php laporan_filter sql injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-89","lang":"en","description":"CWE-89 SQL Injection"}]}],"affected":[{"vendor":"SourceCodester","product":"Laundry Management System","versions":[{"version":"1.0","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in SourceCodester Laundry Management System 1.0 and classified as critical. This issue affects the function laporan_filter of the file /application/controller/Pelanggan.php. The manipulation of the argument jeniskelamin leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259745 was assigned to this vulnerability."},{"lang":"de","value":"Eine kritische Schwachstelle wurde in SourceCodester Laundry Management System 1.0 gefunden. Davon betroffen ist die Funktion laporan_filter der Datei /application/controller/Pelanggan.php. Mit der Manipulation des Arguments jeniskelamin mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":6.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":6.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":6.5,"vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P"}}],"timeline":[{"time":"2024-04-08T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2024-04-08T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-04-08T14:38:06.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"LI YU (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.259745","name":"VDB-259745 | SourceCodester Laundry Management System Pelanggan.php laporan_filter sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.259745","name":"VDB-259745 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.312304","name":"Submit #312304 | Sourcecodester Laundry Management System v1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/fubxx/CVE/blob/main/LaundryManagementSystemSQL2.md","tags":["exploit"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-3464","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-04-09T15:14:52.372164Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-05T17:22:36.789Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T20:12:07.865Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.259745","name":"VDB-259745 | SourceCodester Laundry Management System Pelanggan.php laporan_filter sql injection","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.259745","name":"VDB-259745 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required","x_transferred"]},{"url":"https://vuldb.com/?submit.312304","name":"Submit #312304 | Sourcecodester Laundry Management System v1.0 SQL Injection","tags":["third-party-advisory","x_transferred"]},{"url":"https://github.com/fubxx/CVE/blob/main/LaundryManagementSystemSQL2.md","tags":["exploit","x_transferred"]}]}]}}