CVE-2024-0471: code-projects Human Resource Integrated System dec_service_credits.php sql injection
A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /adminroute/decservicecredits.php. The manipulation of the argument date leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250576.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0471?
CVE-2024-0471 is classified as a critical vulnerability.
How does CVE-2024-0471 affect the Human Resource Integrated System?
CVE-2024-0471 allows for SQL injection due to improper handling of the argument date in the file /admin_route/dec_service_credits.php.
What versions of the Human Resource Integrated System are impacted by CVE-2024-0471?
The vulnerable version of the Human Resource Integrated System affected by CVE-2024-0471 is 1.0.
How can I mitigate the risks associated with CVE-2024-0471?
To mitigate the risks of CVE-2024-0471, it is essential to validate and sanitize all user inputs in the affected application.
What type of attack can be performed using CVE-2024-0471?
CVE-2024-0471 allows attackers to perform SQL injection attacks that can compromise the database.