SQL Injection Vulnerability in Campcodes Online Marriage Registration System
CVE-2024-2777
Summary
The Campcodes Online Marriage Registration System 1.0 has an exploitable SQL injection vulnerability residing in the /admin/application-bwdates-reports-details.php file. The vulnerability is due to improper validation of the 'fromdate' parameter, which allows an attacker to manipulate SQL queries executed by the server. This vulnerability can be exploited remotely, making it particularly hazardous for users of this system. Given its public disclosure, immediate action is recommended to mitigate potential exploitation.
Affected Version(s)
Online Marriage Registration System 1.0
Online Marriage Registration System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published