{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-8138","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2024-08-23T22:23:57.818Z","datePublished":"2024-08-25T00:00:06.105Z","dateUpdated":"2024-08-26T13:46:25.673Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-08-25T00:00:06.105Z"},"title":"code-projects Pharmacy Management System Parameter index.php editManager sql injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-89","lang":"en","description":"CWE-89 SQL Injection"}]}],"affected":[{"vendor":"code-projects","product":"Pharmacy Management System","versions":[{"version":"1.0","status":"affected"}],"modules":["Parameter Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability, which was classified as critical, was found in code-projects Pharmacy Management System 1.0. Affected is the function editManager of the file /index.php?action=editManager of the component Parameter Handler. The manipulation of the argument id as part of String leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available."},{"lang":"de","value":"Es wurde eine Schwachstelle in code-projects Pharmacy Management System 1.0 gefunden. Sie wurde als kritisch eingestuft. Dabei betrifft es die Funktion editManager der Datei /index.php?action=editManager der Komponente Parameter Handler. Durch die Manipulation des Arguments id durch String kann eine sql injection-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung. Dieses Produkt verzichtet auf eine Versionierung und verwendet stattdessen Rolling Releases. Deshalb sind keine Details zu betroffenen oder zu aktualisierende Versionen vorhanden."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":6.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":6.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":6.5,"vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P"}}],"timeline":[{"time":"2024-08-22T00:00:00.000Z","lang":"en","value":"Vulnerability found"},{"time":"2024-08-23T00:00:00.000Z","lang":"en","value":"Vulnerability introduced"},{"time":"2024-08-23T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-08-24T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2024-08-24T09:13:02.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"indifference (VulDB User)","type":"reporter"},{"lang":"en","value":"indifference (VulDB User)","type":"analyst"}],"references":[{"url":"https://vuldb.com/?id.275718","name":"VDB-275718 | code-projects Pharmacy Management System Parameter index.php editManager sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.275718","name":"VDB-275718 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.396817","name":"Submit #396817 | code-projects pharmacy-management-system-in-php-with-source-code v1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/SYQGITHUB/cve/blob/main/sql1.md","tags":["exploit"]},{"url":"https://code-projects.org/","tags":["product"]}]},"adp":[{"affected":[{"vendor":"code-projects","product":"pharmacy_management_system","cpes":["cpe:2.3:a:code-projects:pharmacy_management_system:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1.0","status":"affected"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-08-26T13:44:24.282132Z","id":"CVE-2024-8138","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-08-26T13:46:25.673Z"}}]}}