PT-2024-39381 · Unknown · Codezips Internal Marks Calculation

N3Xu5Cr4Ck37

·

Published

2024-09-20

·

Updated

2025-03-31

·

CVE-2024-9037

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Codezips Internal Marks Calculation version 1.0
Description A critical vulnerability has been found in the software, affecting an unknown function of the file index.php. The manipulation of the tid argument leads to SQL injection, allowing for remote attacks. The exploit has been publicly disclosed.
Recommendations For Codezips Internal Marks Calculation version 1.0, consider disabling the unknown function in the file index.php that is affected by the SQL injection vulnerability until a patch is available. Restrict access to the tid argument to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9037

Affected Products

Codezips Internal Marks Calculation