PT-2024-17895 · Codeastro · Codeastro Simple Loan Management System

John Correche

·

Published

2024-12-30

·

Updated

2025-01-04

·

CVE-2024-13038

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CodeAstro Simple Loan Management System version 1.0
Description A critical issue has been found in the CodeAstro Simple Loan Management System. The problem affects an unknown functionality of the /index.php file in the Login component. Manipulation of the email argument leads to SQL injection. This attack can be launched remotely. The exploit has been made public.
Recommendations For CodeAstro Simple Loan Management System version 1.0, as a temporary workaround, consider restricting access to the /index.php file in the Login component to minimize the risk of exploitation. Avoid using the email argument in the affected functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-13038

Affected Products

Codeastro Simple Loan Management System