PT-2024-37312 · Itsourcecode · Itsourcecode Event Calendar

Code099

+1

·

Published

2024-06-15

·

Updated

2024-07-19

·

CVE-2024-6009

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: itsourcecode Event Calendar version 1.0
Description: A critical issue has been found in the function regConfirm/regDelete of the file process.php. The manipulation of the userId argument leads to SQL injection. The attack can be launched remotely.
Recommendations: For itsourcecode Event Calendar version 1.0, consider disabling the regConfirm/regDelete function in the process.php file until a patch is available. Restrict access to the process.php file to minimize the risk of exploitation. Avoid using the userId argument in the affected function until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-6009

Affected Products

Itsourcecode Event Calendar