SQL Injection Vulnerability in LyLme_spage Product
CVE-2024-9790
Key Information:
- Vendor
LyLme_spage
- Status
- Vendor
- CVE Published:
- 10 October 2024
Badges
What is CVE-2024-9790?
A significant SQL injection vulnerability has been identified in the LyLme_spage system version 1.9.5, specifically within the /admin/sou.php file. This flaw allows an attacker to manipulate the 'id' parameter, leading to unauthorized database access and potential data breaches. The vulnerability can be exploited remotely, making it a serious threat to users of this specific version. Despite attempts to notify LyLme of the issue, there has been no acknowledgment or response, leaving many systems at risk. Immediate action is advised to mitigate potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
LyLme_spage 1.9.5
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
