PT-2024-28879 · Unknown · Puneethreddyhc Online Shopping System

Dirac231

·

Published

2024-08-05

·

Updated

2024-08-14

·

CVE-2024-40498

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PuneethReddyHC Online Shopping system advanced version 1.0
Description The issue allows an attacker to execute arbitrary code. An unauthenticated remote attacker can manipulate the address1 variable in the "register.php" endpoint.
Recommendations For version 1.0, patch immediately and validate user input to prevent exploitation. As a temporary workaround, consider restricting access to the "register.php" endpoint until a patch is available. Avoid using the address1 variable in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-40498

Affected Products

Puneethreddyhc Online Shopping System