SQL Injection Vulnerability in Codezips Pet Shop Management System
CVE-2024-10556
Key Information:
- Vendor
- Codezips
- Status
- Pet Shop Management System
- Vendor
- CVE Published:
- 31 October 2024
Badges
Summary
A serious vulnerability has been identified in the Codezips Pet Shop Management System, specifically in the birdsadd.php file. This vulnerability allows attackers to manipulate the 'id' parameter, enabling SQL injection attacks. These attacks can be initiated remotely, posing significant security risks to affected systems. The nature of this vulnerability allows unauthorized users to gain access to sensitive database information potentially leading to data breaches. It is crucial for users of the Pet Shop Management System to review their systems and apply necessary security measures to mitigate risk. Public disclosure of the exploit has raised concerns among security professionals and users alike, highlighting the importance of vigilance in system updates and security protocols.
Affected Version(s)
Pet Shop Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published