PT-2024-15578 · Code Projects · Code-Projects Online Faculty Clearance

Fabian Ros

·

Published

2024-01-12

·

Updated

2024-05-17

·

CVE-2024-0461

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Online Faculty Clearance version 1.0
Description A critical issue has been found in the HTTP POST Request Handler component of the file deactivate.php. The manipulation of the haydi argument leads to SQL injection. This issue can be exploited remotely.
Recommendations For code-projects Online Faculty Clearance version 1.0, consider disabling the deactivate.php file or restricting access to it until a patch is available. Avoid using the haydi argument in the affected HTTP POST Request Handler until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-0461

Affected Products

Code-Projects Online Faculty Clearance