CVE-2024-10370: Codezips Sales Management System addcustind.php sql injection
Published Oct 25, 2024
·Updated
A vulnerability was found in Codezips Sales Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /addcustind.php. The manipulation of the argument refno leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Codezips Sales Management System=1.0
Event History
Oct 25, 2024
CVE Published
via MITRE·01:31 AM
Data Sourced
via MITRE·01:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10370?
CVE-2024-10370 has been rated as critical.
2
What type of vulnerability is CVE-2024-10370?
CVE-2024-10370 is an SQL injection vulnerability.
3
Which file is affected by CVE-2024-10370?
The affected file is /addcustind.php.
4
How can an attacker exploit CVE-2024-10370?
The vulnerability can be exploited remotely by manipulating the argument refno.
5
Which software version is impacted by CVE-2024-10370?
Codezips Sales Management System version 1.0 is impacted by this vulnerability.