PT-2024-39857 · Unknown · Code-Projects Crud Operation System

Hello_Zty

+1

·

Published

2024-10-10

·

Updated

2024-10-15

·

CVE-2024-9812

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Crud Operation System version 1.0
Description A critical vulnerability was found in the code-projects Crud Operation System. This issue affects the file delete.php and is related to the manipulation of the sid argument, leading to SQL injection. The attack can be initiated remotely.
Recommendations For code-projects Crud Operation System version 1.0, consider restricting access to the delete.php file until a patch is available. As a temporary workaround, avoid using the sid argument in the affected file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-9812

Affected Products

Code-Projects Crud Operation System