PT-2024-16583 · Unknown · Romadebrian Web-Sekolah
Romadebrian
·
Published
2024-11-05
·
Updated
2024-11-09
·
CVE-2024-10841
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
romadebrian WEB-Sekolah version 1.0
Description
A critical vulnerability was found in the Mail Handler component of romadebrian WEB-Sekolah. The manipulation of the
Name argument in the /Proses Kirim.php file leads to SQL injection. The attack can be launched remotely. Other parameters might be affected as well.Recommendations
For romadebrian WEB-Sekolah version 1.0, update to the latest version and apply all recommended patches to safeguard your systems. As a temporary workaround, consider restricting access to the
/Proses Kirim.php file and the Name argument to minimize the risk of exploitation.Exploit
Fix
Improper Neutralization
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Romadebrian Web-Sekolah