PT-2024-20273 · Unknown · Code-Projects Computer Science Time Table System

Aaditya Singh Rajawat

·

Published

2024-03-13

·

Updated

2024-03-14

·

CVE-2024-24105

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Code-projects Computer Science Time Table System version 1.0
Description The issue allows attackers to run arbitrary code via the "adminFormvalidation.php" endpoint. This can be exploited by injecting malicious SQL code, potentially leading to unauthorized access or data manipulation.
Recommendations For Code-projects Computer Science Time Table System version 1.0, consider restricting access to the "adminFormvalidation.php" endpoint until a patch is available. As a temporary workaround, validate and sanitize all user input to prevent SQL injection attacks.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-24105

Affected Products

Code-Projects Computer Science Time Table System