SQL Injection Vulnerability in 1000 Projects Attendance Tracking Management System
CVE-2024-13005
Key Information:
- Vendor
- 1000 Projects
- Status
- Attendance Tracking Management System
- Vendor
- CVE Published:
- 29 December 2024
Badges
Summary
A significant vulnerability exists in the 1000 Projects Attendance Tracking Management System version 1.0, specifically in the /admin/attendance_action.php file, where improper handling of the attendance_id argument enables an SQL injection attack. This flaw allows attackers to manipulate queries sent to the database, facilitating unauthorized access to sensitive data and potential control over the database. The issue can be exploited remotely, posing a substantial risk to systems that utilize this attendance management solution. This vulnerability has been made public, indicating an urgent need for remediation to avert potential exploits.
Affected Version(s)
Attendance Tracking Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved