PT-2024-5174 · Unknown · Tailoring Management System
Zhenyu Xiao
·
Published
2024-07-14
·
Updated
2024-08-21
·
CVE-2024-6735
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Tailoring Management System version 1.0
Description:
A critical issue has been identified in the Tailoring Management System, affecting the setgeneral.php file. This issue is related to the lack of protection against SQL query structure manipulation, which can lead to SQL injection. The manipulation of the
sitename, email, mobile, sms, and currency arguments can initiate a remote attack, potentially allowing an attacker to execute arbitrary SQL code, gain unauthorized access to read, modify, or delete data, or cause a denial of service by sending specially crafted requests.Recommendations:
For Tailoring Management System version 1.0, as a temporary workaround, consider restricting access to the setgeneral.php file and avoiding the use of the
sitename, email, mobile, sms, and currency parameters until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tailoring Management System