SQL Injection Vulnerability in itsourcecode Tailoring Management System by itsourcecode
CVE-2024-11074
9.8CRITICAL
Summary
A SQL injection vulnerability in the itsourcecode Tailoring Management System version 1.0 has been identified in the file /incadd.php. By manipulating the parameters 'inccat,' 'desc,' 'date,' and 'amount,' an attacker can execute arbitrary SQL queries on the underlying database. This vulnerability can be exploited remotely, posing significant risks to data integrity and security within applications utilizing the affected software. Given that the specific parameters mentioned may allow for unauthorized data access or manipulation, it is critical for users to apply security updates or mitigations as soon as possible.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published