CVE-2024-10167: Codezips Sales Management System deletecustind.php sql injection
Published Oct 20, 2024
·Updated
A vulnerability classified as critical has been found in Codezips Sales Management System 1.0. This affects an unknown part of the file deletecustind.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Codezips Sales Management System=1.0
Event History
Oct 20, 2024
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10167?
CVE-2024-10167 is classified as a critical vulnerability.
2
What is the impact of CVE-2024-10167?
CVE-2024-10167 allows for SQL injection through manipulation of the 'id' argument.
3
How can I fix CVE-2024-10167?
To fix CVE-2024-10167, validate and sanitize the 'id' input in the deletecustind.php file.
4
Which software versions are affected by CVE-2024-10167?
CVE-2024-10167 affects Codezips Sales Management System version 1.0.
5
Can CVE-2024-10167 be exploited remotely?
Yes, CVE-2024-10167 can be exploited remotely.