Itsourcecode · Itsourcecode Event Calendar · CVE-2024-6009
Name of the Vulnerable Software and Affected Versions:
itsourcecode Event Calendar version 1.0
Description:
A critical issue has been found in the function `regConfirm/regDelete` of the file `process.php`. The manipulation of the `userId` argument leads to SQL injection. The attack can be launched remotely.
Recommendations:
For itsourcecode Event Calendar version 1.0, consider disabling the `regConfirm/regDelete` function in the `process.php` file until a patch is available. Restrict access to the `process.php` file to minimize the risk of exploitation. Avoid using the `userId` argument in the affected function until the issue is resolved.