CVE-2024-10423: Project Worlds Student Project Allocation System Project Selection Page project_selection.php sql injection
A vulnerability, which was classified as critical, was found in Project Worlds Student Project Allocation System 1.0. Affected is an unknown function of the file /student/projectselection/projectselection.php of the component Project Selection Page. The manipulation of the argument projectid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10423?
CVE-2024-10423 is classified as a critical vulnerability.
What component is affected by CVE-2024-10423?
CVE-2024-10423 affects the Project Selection Page in the file /student/project_selection/project_selection.php.
How do I fix CVE-2024-10423?
To fix CVE-2024-10423, it is recommended to update the Project Worlds Student Project Allocation System to a version that addresses this vulnerability.
What versions of the software are impacted by CVE-2024-10423?
CVE-2024-10423 impacts version 1.0 of the Project Worlds Student Project Allocation System.
Can CVE-2024-10423 lead to further exploitation?
Yes, due to its critical nature, CVE-2024-10423 can potentially lead to further exploitation if not addressed promptly.