PT-2024-17807 · Code Projects · Simple Admin Panel

Havook

·

Published

2024-12-26

·

Updated

2024-12-26

·

CVE-2024-12937

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Simple Admin Panel version 1.0
Description A critical issue was found in the Simple Admin Panel, affecting an unknown function of the file addVariationController.php. The manipulation of the qty argument leads to SQL injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For version 1.0, consider disabling the unknown function in the addVariationController.php file until a patch is available. Restrict access to the qty argument to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-12937

Affected Products

Simple Admin Panel