First published: Fri Oct 25 2024(Updated: )
A vulnerability was found in Codezips Sales Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /addstock.php. The manipulation of the argument prodtype leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Codezips Sales Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10368 has been classified as critical due to the potential for remote SQL injection.
To fix CVE-2024-10368, it is recommended to apply input validation and use prepared statements to prevent SQL injection.
CVE-2024-10368 affects version 1.0 of Codezips Sales Management System.
Yes, CVE-2024-10368 can be exploited remotely through the vulnerable /addstock.php function.
CVE-2024-10368 is associated with SQL injection attacks that can compromise the database.