PT-2024-18339 · Unknown · Codeastro House Rental Management System

Mooooon

·

Published

2024-02-23

·

Updated

2024-12-06

·

CVE-2024-1824

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CodeAstro House Rental Management System version 1.0
Description A critical issue has been found in the CodeAstro House Rental Management System, affecting some unknown functionality of the file signing.php. The manipulation of the uname/password argument leads to SQL injection. The attack may be launched remotely.
Recommendations For CodeAstro House Rental Management System version 1.0, consider disabling the vulnerable functionality in the signing.php file until a patch is available. Restrict access to the signing.php file to minimize the risk of exploitation. Avoid using the uname and password arguments in the affected functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-1824

Affected Products

Codeastro House Rental Management System