PT-2024-16586 · Unknown · 1000 Projects Bookstore Management System

Lime

·

Published

2024-11-05

·

Updated

2024-11-09

·

CVE-2024-10845

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 1000 Projects Bookstore Management System version 1.0
Description A critical issue has been found in the 1000 Projects Bookstore Management System, affecting unknown code in the file book detail.php. The manipulation of the id argument leads to SQL injection. This issue can be initiated remotely.
Recommendations For version 1.0, update to the latest version to mitigate risks. As a temporary workaround, consider restricting access to the book detail.php file until a patch is available. Avoid using the id argument in the affected file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Neutralization

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10845

Affected Products

1000 Projects Bookstore Management System