PT-2024-17807 · Code Projects · Simple Admin Panel
Havook
·
Published
2024-12-26
·
Updated
2024-12-26
·
CVE-2024-12937
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
code-projects Simple Admin Panel version 1.0
Description
A critical issue was found in the Simple Admin Panel, affecting an unknown function of the file addVariationController.php. The manipulation of the
qty argument leads to SQL injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.Recommendations
For version 1.0, consider disabling the unknown function in the addVariationController.php file until a patch is available. Restrict access to the
qty argument to minimize the risk of exploitation.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simple Admin Panel