CVE-2024-0477: code-projects Fighting Cock Information System update-deworm.php sql injection
A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/action/update-deworm.php. The manipulation of the argument usagedeworm leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-250582 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0477?
CVE-2024-0477 is classified as a critical vulnerability due to the potential for SQL injection attacks.
How do I fix CVE-2024-0477?
To mitigate CVE-2024-0477, it is essential to sanitize and validate user inputs for the 'usage_deworm' parameter in the affected PHP file.
Which software is affected by CVE-2024-0477?
CVE-2024-0477 affects the Fighting Cock Information System version 1.0.
What type of vulnerability is CVE-2024-0477?
CVE-2024-0477 is an SQL injection vulnerability that allows attackers to manipulate database queries.
What is the potential impact of exploiting CVE-2024-0477?
Exploiting CVE-2024-0477 can lead to unauthorized access to the database, data manipulation, or data leakage.