CVE-2024-5101
published 2024-05-19CVE-2024-5101: A vulnerability was found in SourceCodester Simple Inventory System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.61%
45.4th percentile
A vulnerability was found in SourceCodester Simple Inventory System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file updateproduct.php. The manipulation of the argument ITEM leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265084.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| argie | simple_inventory_system | — | — |
| sourcecodester | simple_inventory_system | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-36921 kernel: wifi: iwlwifi: mvm: guard against invalid STA ID on removal
bugzilla·2024-06-03·CVSS 7.8
CVE-2024-36921 [HIGH] CVE-2024-36921 kernel: wifi: iwlwifi: mvm: guard against invalid STA ID on removal
CVE-2024-36921 kernel: wifi: iwlwifi: mvm: guard against invalid STA ID on removal
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mvm: guard against invalid STA ID on removal
The Linux kernel CVE team has assigned CVE-2024-36921 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024053039-CVE-2024-36921-9f90@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2284514]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHSA-2024:5101
-
Bugzilla
CVE-2023-52777 kernel: wifi: ath11k: fix gtk offload status event locking
bugzilla·2024-05-22·CVSS 7.8
CVE-2023-52777 [HIGH] CVE-2023-52777 kernel: wifi: ath11k: fix gtk offload status event locking
CVE-2023-52777 kernel: wifi: ath11k: fix gtk offload status event locking
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix gtk offload status event locking
The Linux kernel CVE team has assigned CVE-2023-52777 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024052152-CVE-2023-52777-2f32@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHSA-2024:5101
Bugzilla
CVE-2021-47408 kernel: netfilter: conntrack: serialize hash resizes and cleanups
bugzilla·2024-05-22·CVSS 5.5
CVE-2021-47408 [MEDIUM] CVE-2021-47408 kernel: netfilter: conntrack: serialize hash resizes and cleanups
CVE-2021-47408 kernel: netfilter: conntrack: serialize hash resizes and cleanups
In the Linux kernel, the following vulnerability has been resolved:
netfilter: conntrack: serialize hash resizes and cleanups
The Linux kernel CVE team has assigned CVE-2021-47408 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024052151-CVE-2021-47408-ad88@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHSA-2024:5101
Bugzilla
CVE-2023-52847 kernel: media: bttv: fix use after free error due to btv->timeout timer
bugzilla·2024-05-22·CVSS 7.0
CVE-2023-52847 [HIGH] CVE-2023-52847 kernel: media: bttv: fix use after free error due to btv->timeout timer
CVE-2023-52847 kernel: media: bttv: fix use after free error due to btv->timeout timer
In the Linux kernel, the following vulnerability has been resolved:
media: bttv: fix use after free error due to btv->timeout timer
The Linux kernel CVE team has assigned CVE-2023-52847 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024052113-CVE-2023-52847-a551@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHSA-2024:5101
Bugzilla
CVE-2024-35910 kernel: tcp: properly terminate timers for kernel sockets
bugzilla·2024-05-20·CVSS 5.8
CVE-2024-35910 [MEDIUM] CVE-2024-35910 kernel: tcp: properly terminate timers for kernel sockets
CVE-2024-35910 kernel: tcp: properly terminate timers for kernel sockets
In the Linux kernel, the following vulnerability has been resolved:
tcp: properly terminate timers for kernel sockets
The Linux kernel CVE team has assigned CVE-2024-35910 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024051955-CVE-2024-35910-5f95@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2281642]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHSA-2024:5101
---
This issue has b
Bugzilla
CVE-2024-35810 kernel: drm/vmwgfx: Fix the lifetime of the bo cursor memory
bugzilla·2024-05-17·CVSS 5.5
CVE-2024-35810 [MEDIUM] CVE-2024-35810 kernel: drm/vmwgfx: Fix the lifetime of the bo cursor memory
CVE-2024-35810 kernel: drm/vmwgfx: Fix the lifetime of the bo cursor memory
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Fix the lifetime of the bo cursor memory
The Linux kernel CVE team has assigned CVE-2024-35810 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024051741-CVE-2024-35810-1b33@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2281216]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHSA-2024:5101
---
This issue
Bugzilla
CVE-2024-35807 kernel: ext4: fix corruption during on-line resize
bugzilla·2024-05-17·CVSS 5.5
CVE-2024-35807 [MEDIUM] CVE-2024-35807 kernel: ext4: fix corruption during on-line resize
CVE-2024-35807 kernel: ext4: fix corruption during on-line resize
In the Linux kernel, the following vulnerability has been resolved:
ext4: fix corruption during on-line resize
The Linux kernel CVE team has assigned CVE-2024-35807 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024051740-CVE-2024-35807-2a9e@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2281222]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHSA-2024:5101
---
This issue has been addressed
Bugzilla
CVE-2024-27388 kernel: SUNRPC: fix some memleaks in gssx_dec_option_array
bugzilla·2024-05-01·CVSS 5.5
CVE-2024-27388 [MEDIUM] CVE-2024-27388 kernel: SUNRPC: fix some memleaks in gssx_dec_option_array
CVE-2024-27388 kernel: SUNRPC: fix some memleaks in gssx_dec_option_array
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: fix some memleaks in gssx_dec_option_array
The Linux kernel CVE team has assigned CVE-2024-27388 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050135-CVE-2024-27388-04eb@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278536]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHSA-2024:5101
Bugzilla
CVE-2023-52648 kernel: drm/vmwgfx: Unmap the surface before resetting it on a plane state
bugzilla·2024-05-01·CVSS 5.5
CVE-2023-52648 [MEDIUM] CVE-2023-52648 kernel: drm/vmwgfx: Unmap the surface before resetting it on a plane state
CVE-2023-52648 kernel: drm/vmwgfx: Unmap the surface before resetting it on a plane state
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Unmap the surface before resetting it on a plane state
The Linux kernel CVE team has assigned CVE-2023-52648 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050122-CVE-2023-52648-4e0d@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278540]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHS
Bugzilla
CVE-2024-26958 kernel: nfs: fix UAF in direct writes
bugzilla·2024-05-01·CVSS 7.8
CVE-2024-26958 [HIGH] CVE-2024-26958 kernel: nfs: fix UAF in direct writes
CVE-2024-26958 kernel: nfs: fix UAF in direct writes
In the Linux kernel, the following vulnerability has been resolved:
nfs: fix UAF in direct writes
The Linux kernel CVE team has assigned CVE-2024-26958 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050129-CVE-2024-26958-6c15@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278183]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHSA-2024:5101
---
This issue has been addressed in the following products:
Bugzilla
CVE-2024-26940 kernel: drm/vmwgfx: Create debugfs ttm_resource_manager entry only if needed
bugzilla·2024-05-01·CVSS 5.5
CVE-2024-26940 [MEDIUM] CVE-2024-26940 kernel: drm/vmwgfx: Create debugfs ttm_resource_manager entry only if needed
CVE-2024-26940 kernel: drm/vmwgfx: Create debugfs ttm_resource_manager entry only if needed
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Create debugfs ttm_resource_manager entry only if needed
The Linux kernel CVE team has assigned CVE-2024-26940 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050125-CVE-2024-26940-1785@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278219]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata
Bugzilla
CVE-2024-26837 kernel: net: bridge: switchdev: Skip MDB replays of deferred events on offload
bugzilla·2024-04-17·CVSS 4.7
CVE-2024-26837 [MEDIUM] CVE-2024-26837 kernel: net: bridge: switchdev: Skip MDB replays of deferred events on offload
CVE-2024-26837 kernel: net: bridge: switchdev: Skip MDB replays of deferred events on offload
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: switchdev: Skip MDB replays of deferred events on offload
The Linux kernel CVE team has assigned CVE-2024-26837 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041715-CVE-2024-26837-753c@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275581]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/er
Bugzilla
CVE-2024-26843 kernel: efi: runtime: Fix potential overflow of soft-reserved region size
bugzilla·2024-04-17·CVSS 6.0
CVE-2024-26843 [MEDIUM] CVE-2024-26843 kernel: efi: runtime: Fix potential overflow of soft-reserved region size
CVE-2024-26843 kernel: efi: runtime: Fix potential overflow of soft-reserved region size
In the Linux kernel, the following vulnerability has been resolved:
efi: runtime: Fix potential overflow of soft-reserved region size
The Linux kernel CVE team has assigned CVE-2024-26843 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041716-CVE-2024-26843-51a0@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275566]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHSA-
Bugzilla
CVE-2024-26740 kernel: net/sched: act_mirred: use the backlog for mirred ingress
bugzilla·2024-04-04·CVSS 5.5
CVE-2024-26740 [MEDIUM] CVE-2024-26740 kernel: net/sched: act_mirred: use the backlog for mirred ingress
CVE-2024-26740 kernel: net/sched: act_mirred: use the backlog for mirred ingress
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_mirred: use the backlog for mirred ingress
The Linux kernel CVE team has assigned CVE-2024-26740 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040300-CVE-2024-26740-4d6f@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273269]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHSA-2024:5101
---
Bugzilla
CVE-2023-52623 kernel: SUNRPC: Fix a suspicious RCU usage warning
bugzilla·2024-03-26·CVSS 5.5
CVE-2023-52623 [MEDIUM] CVE-2023-52623 kernel: SUNRPC: Fix a suspicious RCU usage warning
CVE-2023-52623 kernel: SUNRPC: Fix a suspicious RCU usage warning
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: Fix a suspicious RCU usage warning
The Linux kernel CVE team has assigned CVE-2023-52623 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/[email protected]/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2271687]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5102 https://access.redhat.com/errata/RHSA-2024:5102
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://acce
Bugzilla
CVE-2023-28746 kernel: Local information disclosure on Intel(R) Atom(R) processors
bugzilla·2024-03-21·CVSS 6.5
CVE-2023-28746 [MEDIUM] CVE-2023-28746 kernel: Local information disclosure on Intel(R) Atom(R) processors
CVE-2023-28746 kernel: Local information disclosure on Intel(R) Atom(R) processors
Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00898.html
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2270731]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHSA-2024:5101
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:8158 htt
https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Inventory%20System%20Sql%20Inject-4.mdhttps://vuldb.com/?ctiid.265084https://vuldb.com/?id.265084https://vuldb.com/?submit.337059https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Inventory%20System%20Sql%20Inject-4.mdhttps://vuldb.com/?ctiid.265084https://vuldb.com/?id.265084https://vuldb.com/?submit.337059
2024-05-19
Published