CVE-2024-0461: code-projects Online Faculty Clearance HTTP POST Request deactivate.php sql injection
A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been classified as critical. Affected is an unknown function of the file deactivate.php of the component HTTP POST Request Handler. The manipulation of the argument haydi leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250566 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0461?
CVE-2024-0461 has been classified as critical due to its potential for SQL injection.
How do I fix CVE-2024-0461?
To fix CVE-2024-0461, you should sanitize inputs in the deactivate.php file to prevent SQL injection.
What components are affected by CVE-2024-0461?
CVE-2024-0461 affects the Online Faculty Clearance version 1.0, specifically the HTTP POST Request Handler component.
What type of vulnerability is CVE-2024-0461?
CVE-2024-0461 is an SQL injection vulnerability that arises from improper handling of the haydi parameter.
What are the potential impacts of CVE-2024-0461?
Exploitation of CVE-2024-0461 could allow an attacker to execute arbitrary SQL queries, compromising the database security.