CVE-2024-10368: Codezips Sales Management System addstock.php sql injection
A vulnerability was found in Codezips Sales Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /addstock.php. The manipulation of the argument prodtype leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10368?
CVE-2024-10368 has been classified as critical due to the potential for remote SQL injection.
How do I fix CVE-2024-10368?
To fix CVE-2024-10368, it is recommended to apply input validation and use prepared statements to prevent SQL injection.
Which software versions are affected by CVE-2024-10368?
CVE-2024-10368 affects version 1.0 of Codezips Sales Management System.
Can CVE-2024-10368 be exploited remotely?
Yes, CVE-2024-10368 can be exploited remotely through the vulnerable /addstock.php function.
What kind of attack is associated with CVE-2024-10368?
CVE-2024-10368 is associated with SQL injection attacks that can compromise the database.