Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Usercode099

#25704of 53,608
9.8Total CVSS
Vulnerabilities · 1
PT-2024-37312
9.8
2024-06-15
Itsourcecode · Itsourcecode Event Calendar · CVE-2024-6009
Name of the Vulnerable Software and Affected Versions: itsourcecode Event Calendar version 1.0 Description: A critical issue has been found in the function `regConfirm/regDelete` of the file `process.php`. The manipulation of the `userId` argument leads to SQL injection. The attack can be launched remotely. Recommendations: For itsourcecode Event Calendar version 1.0, consider disabling the `regConfirm/regDelete` function in the `process.php` file until a patch is available. Restrict access to the `process.php` file to minimize the risk of exploitation. Avoid using the `userId` argument in the affected function until the issue is resolved.