CVE-2024-0475: code-projects Dormitory Management System modifyuser.php sql injection
A vulnerability, which was classified as critical, has been found in code-projects Dormitory Management System 1.0. Affected by this issue is some unknown functionality of the file modifyuser.php. The manipulation of the argument userid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250580.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0475?
CVE-2024-0475 is classified as a critical vulnerability due to its potential impact on database integrity.
What type of vulnerability is CVE-2024-0475?
CVE-2024-0475 is an SQL injection vulnerability affecting the 'modifyuser.php' file in the Dormitory Management System.
How do I fix CVE-2024-0475?
To fix CVE-2024-0475, sanitize and validate input parameters in the 'modifyuser.php' file to prevent SQL injection.
Which software version is affected by CVE-2024-0475?
CVE-2024-0475 affects version 1.0 of the Dormitory Management System by code-projects.
What is the potential impact of exploiting CVE-2024-0475?
Exploitation of CVE-2024-0475 may allow an attacker to execute arbitrary SQL queries, potentially compromising sensitive data.