Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

蓝翔技校王主任

#28013of 53,635
9.1Total CVSS
Vulnerabilities · 1
PT-2024-36530
9.1
2024-12-17
Unknown · 1000Projects Bookstore Management System Php Mysql Project · CVE-2024-55496
**Name of the Vulnerable Software and Affected Versions** 1000projects Bookstore Management System PHP MySQL Project version 1.0 **Description** A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project. This issue affects some unknown functionality of the "add company.php" file. Actions on the `delete` parameter result in SQL injection. **Recommendations** For version 1.0, consider disabling the `delete` parameter in the "add company.php" file until a patch is available to prevent SQL injection attacks. Restrict access to the "add company.php" file to minimize the risk of exploitation. Avoid using the `delete` parameter in the affected functionality until the issue is resolved.