SQL Injection Vulnerability in Code-Projects Simple Admin Panel 1.0
CVE-2024-12928

5.3MEDIUM

Key Information:

Vendor
CVE Published:
26 December 2024

Summary

A significant vulnerability has been identified in version 1.0 of Code-Projects' Simple Admin Panel. This security flaw arises from improper handling of the 'c_name' argument, making the system susceptible to SQL injection attacks. Attackers can exploit this weakness remotely, allowing them to manipulate the underlying database and potentially exfiltrate sensitive data. The disclosure of this vulnerability has raised concerns within the cybersecurity community, highlighting the urgency for users to apply necessary mitigations and updates.

Affected Version(s)

Simple Admin Panel 1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

Credit

Fergod (VulDB User)
.