SQL Injection Vulnerability in Code-Projects Budget Management Application
CVE-2024-5048
Key Information:
- Vendor
- Code-projects
- Status
- Budget Management
- Vendor
- CVE Published:
- 17 May 2024
Badges
Summary
A serious SQL injection vulnerability has been identified in the Code-Projects Budget Management application version 1.0. This security flaw is associated with the file /index.php and arises from improper handling of the 'edit' parameter. Attackers can exploit this vulnerability remotely, allowing them to execute arbitrary SQL commands, which could result in unauthorized access to the application's database. The exploit has been made public, raising concerns about potential misuse. Organizations using this application are advised to take immediate actions to safeguard their systems against possible attacks.
Affected Version(s)
Budget Management 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved