Sports Management System Project 1.0 vulnerable to SQL Injection
CVE-2024-46078
7.5HIGH
What is CVE-2024-46078?
The itsourcecode Sports Management System Project 1.0 contains a vulnerability in the 'delete_category' function located in the 'sports_scheduling/player.php' file. This vulnerability allows attackers to exploit the input parameter 'id', facilitating unauthorized access to the database. By executing crafted SQL queries, an attacker could manipulate, modify, or delete data, leading to significant security risks. It is imperative for users to implement immediate corrective measures to secure their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
