CVE-2024-0473

A vulnerability classified as critical has been found in code-projects Dormitory Management System 1.0. Affected is an unknown function of the file comment.php. The manipulation of the argument com leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250578 is the identifier assigned to this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:code-projects:dormitory_management_system:1.0:*:*:*:*:*:*:*

History

19 Jan 2024, 14:16

Type Values Removed Values Added
CPE cpe:2.3:a:code-projects:dormitory_management_system:1.0:*:*:*:*:*:*:*
References () https://github.com/yingqian1984/FirePunch/blob/main/7-Dormitory%20Management%20System%20has%20SQL%20injection%20vulnerabilities%20comment.php.pdf - () https://github.com/yingqian1984/FirePunch/blob/main/7-Dormitory%20Management%20System%20has%20SQL%20injection%20vulnerabilities%20comment.php.pdf - Broken Link
References () https://vuldb.com/?ctiid.250578 - () https://vuldb.com/?ctiid.250578 - Permissions Required, Third Party Advisory
References () https://vuldb.com/?id.250578 - () https://vuldb.com/?id.250578 - Third Party Advisory
CVSS v2 : 6.5
v3 : 6.3
v2 : 6.5
v3 : 9.8
Summary
  • (es) Una vulnerabilidad ha sido encontrada en code-projects Dormitory Management System 1.0 y clasificada como crítica. Una función desconocida del archivo comment.php es afectada por esta vulnerabilidad. La manipulación del argumento com conduce a la inyección de SQL. Es posible lanzar el ataque de forma remota. La explotación ha sido divulgada al público y puede utilizarse. VDB-250578 es el identificador asignado a esta vulnerabilidad.
First Time Code-projects dormitory Management System
Code-projects

12 Jan 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-12 22:15

Updated : 2024-04-11 01:23


NVD link : CVE-2024-0473

Mitre link : CVE-2024-0473

CVE.ORG link : CVE-2024-0473


JSON object : View

Products Affected

code-projects

  • dormitory_management_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')