SQL Injection Vulnerability in itsourcecode Placement Management System
CVE-2024-7449
Key Information:
- Vendor
- Itsourcecode
- Vendor
- CVE Published:
- 4 August 2024
Badges
Summary
A serious SQL injection vulnerability has been identified in the itsourcecode Placement Management System version 1.0, specifically impacting the login.php file. It occurs when the 'email' parameter is manipulated, potentially allowing attackers to execute unauthorized SQL commands on the database. This vulnerability can be exploited remotely, increasing the risk of data breaches and unauthorized access. The exploit details have been publicly disclosed, highlighting the urgent need for affected users to implement remediation steps.
Affected Version(s)
Placement Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved