PT-2024-6563 · Campcodes · Campcodes House Rental Management System
Ssl_Seven
+2
·
Published
2024-03-26
·
Updated
2025-02-20
·
CVE-2024-2916
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Campcodes House Rental Management System version 1.0
Description:
The issue is related to a lack of protection against SQL query structure exploitation in the Campcodes House Rental Management System. This allows a remote attacker to execute arbitrary SQL queries. The manipulation of the
username argument in the file ajax.php leads to SQL injection. The exploit has been disclosed to the public and may be used. The attack can be launched remotely.Recommendations:
For Campcodes House Rental Management System version 1.0, consider disabling the
ajax.php file or restricting access to it until a patch is available. As a temporary workaround, avoid using the username argument in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Campcodes House Rental Management System