SQL Injection Vulnerability in Code-Projects Simple Admin Panel 1.0
CVE-2024-12928
5.3MEDIUM
Summary
A significant vulnerability has been identified in version 1.0 of Code-Projects' Simple Admin Panel. This security flaw arises from improper handling of the 'c_name' argument, making the system susceptible to SQL injection attacks. Attackers can exploit this weakness remotely, allowing them to manipulate the underlying database and potentially exfiltrate sensitive data. The disclosure of this vulnerability has raised concerns within the cybersecurity community, highlighting the urgency for users to apply necessary mitigations and updates.
Affected Version(s)
Simple Admin Panel 1.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Credit
Fergod (VulDB User)