CVE-2024-7841
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Aug 15, 2024
Updated: Aug 19, 2024
CWE ID 89
Summary
CVE-2024-7841 is a newly disclosed critical vulnerability that impacts the SourceCodester Clinics Patient Management System version 1.0. The issue lies in the /pms/ajax/check_user_name.php file, where an sql injection vulnerability has been discovered. An attacker can exploit this flaw by manipulating the user_name argument, allowing them to execute malicious SQL statements remotely. The exploit for this vulnerability has been made public, increasing the risk of successful attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share