PT-2024-16404 · Unknown · Itsourcecode Tailoring Management System Project

Cdeter

·

Published

2024-11-01

·

Updated

2024-11-05

·

CVE-2024-10609

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions itsourcecode Tailoring Management System Project version 1.0
Description A critical issue has been found in the itsourcecode Tailoring Management System Project. This issue affects an unknown part of the file typeadd.php. The manipulation of the sex argument leads to SQL injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For itsourcecode Tailoring Management System Project version 1.0, as a temporary workaround, consider restricting access to the vulnerable file typeadd.php until a patch is available. Avoid using the sex argument in the affected part of the file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-10609

Affected Products

Itsourcecode Tailoring Management System Project