SQL Injection Vulnerability in Codezips Project Management System
CVE-2024-12926
Key Information:
- Vendor
- Codezips
- Status
- Project Management System
- Vendor
- CVE Published:
- 25 December 2024
Badges
Summary
The Codezips Project Management System version 1.0 contains a vulnerability related to SQL injection found in the advanced.php file located in the /pages/forms/ directory. An attacker can manipulate the 'name' parameter, allowing for unauthorized access to the database. This exploitation can be executed remotely, making the system susceptible to potential database breaches. Since the vulnerability has been disclosed publicly, it poses a risk to users, especially if other parameters are also affected. It is crucial for organizations using this software to apply necessary security patches and monitor their systems closely.
Affected Version(s)
Project Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved