PT-2024-38067 · Unknown · Itsourcecode Tailoring Management System

Dixinwang

·

Published

2024-07-24

·

Updated

2024-11-02

·

CVE-2024-7081

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions itsourcecode Tailoring Management System version 1.0
Description A critical issue affects some unknown functionality of the file expcatadd.php. The manipulation of the id or title argument leads to SQL injection. The attack can be launched remotely.
Recommendations For itsourcecode Tailoring Management System version 1.0, consider restricting access to the expcatadd.php file until a patch is available. As a temporary workaround, avoid using the id and title arguments in the affected functionality to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-7081

Affected Products

Itsourcecode Tailoring Management System