CVE-2024-10355

MEDIUM

SourceCodester Petrol Pump Management Software 1.0 - SQL Injection via /admin/invoice.php id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-10355. PoCs published by K1nakoo.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2024-10355, an SQL injection vulnerability in SourceCodester Petrol Pump Management Software v1.0. It includes vulnerability root cause analysis, HTTP request examples, and sqlmap payloads demonstrating exploitation via boolean-based blind, time-based blind, stacked queries, and UNION-based techniques.

Description

A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/invoice.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Exploits (1)

nomisec WRITEUP
by K1nakoo · poc
https://github.com/K1nakoo/CVE-2024-10355

This repository provides a detailed technical analysis of CVE-2024-10355, an SQL injection vulnerability in SourceCodester Petrol Pump Management Software v1.0. It includes vulnerability root cause analysis, HTTP request examples, and sqlmap payloads demonstrating exploitation via boolean-based blind, time-based blind, stacked queries, and UNION-based techniques.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: SourceCodester Petrol Pump Management Software v1.0
No auth needed
Prerequisites: Network access to the target application · SQLmap or similar SQL injection tool
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.281702
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.281702
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.430077

Scores

CVSS v3 4.7
EPSS 0.0097
EPSS Percentile 57.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
mayurik/petrol_pump_management 1.0
Published Oct 25, 2024
Tracked Since Feb 18, 2026