code-projects Pharmacy Management System 1.0 manage_supplier.php?action=search text SQL Injection

Wuro vulnerability wey an yi classify sey kura an gano shi a cikin code-projects Pharmacy Management System 1.0. Gaskiya, $software_function na da matsala; idan ba a sani ba, to wata aiki ce da ba a sani ba, $software_library na cikin lissafi, /php/manage_supplier.php?action=search na cikin fayil, $software_component na cikin sashi. Ngam manipulation of the argument text shi SQL Injection. CWE shidin ka a yi bayani matsala sai ya kai CWE-89. Gaskiya, laifi an fitar da shi 10/16/2024. Advisory ɗin ana rabawa don saukewa a gist.github.com. Wannan rauni ana sayar da shi da suna CVE-2024-10022. Ngam yiɗi ka a tuma ndiyam ka nder internet. Tekinikal bayani ga. Kuma, exploit ɗin yana akwai. Wuro exploit ɗin an bayyana shi ga jama'a kuma za a iya amfani da shi. A sa'i, exploit might be approx. USD $0-$5k ndiyam. Á wúro huɗɗi-na-gaskiya. Wona yiwuwa a zazzage exploit a gist.github.com. Kama 0-day, an ndiyam a wuro be $0-$5k. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.

1 Goyarwa · 56 Datenpunkte

FurɗeSúgá
10/16/2024 08:10
software_vendorcode-projects
software_namePharmacy Management System
software_version1.0
software_file/php/manage_supplier.php?action=search
software_argumenttext
vulnerability_cweCWE-89 (SQL Injection)
vulnerability_risk2
cvss3_vuldb_avN
cvss3_vuldb_acL
cvss3_vuldb_uiN
cvss3_vuldb_sU
cvss3_vuldb_cL
cvss3_vuldb_iL
cvss3_vuldb_aL
cvss3_vuldb_eP
cvss3_vuldb_rcR
advisory_urlhttps://gist.github.com/higordiego/2bd0a94e480906a60ce83b8a4ec26957
exploit_availability1
exploit_publicity1
exploit_urlhttps://gist.github.com/higordiego/2bd0a94e480906a60ce83b8a4ec26957
source_cveCVE-2024-10022
cna_responsibleVulDB
software_typeProject Management Software
cvss2_vuldb_avN
cvss2_vuldb_acL
cvss2_vuldb_ciP
cvss2_vuldb_iiP
cvss2_vuldb_aiP
cvss2_vuldb_ePOC
cvss2_vuldb_rcUR
cvss4_vuldb_avN
cvss4_vuldb_acL
cvss4_vuldb_uiN
cvss4_vuldb_vcL
cvss4_vuldb_viL
cvss4_vuldb_vaL
cvss4_vuldb_eP
cvss2_vuldb_auS
cvss2_vuldb_rlND
cvss3_vuldb_prL
cvss3_vuldb_rlX
cvss4_vuldb_atN
cvss4_vuldb_prL
cvss4_vuldb_scN
cvss4_vuldb_siN
cvss4_vuldb_saN
cvss2_vuldb_basescore6.5
cvss2_vuldb_tempscore5.6
cvss3_vuldb_basescore6.3
cvss3_vuldb_tempscore5.7
cvss3_meta_basescore6.3
cvss3_meta_tempscore5.7
cvss4_vuldb_bscore5.3
cvss4_vuldb_btscore2.1
advisory_date1729029600 (10/16/2024)
price_0day$0-$5k

Want to stay up to date on a daily basis?

Enable the mail alert feature now!