CVE-2024-10699: code-projects Wazifa System logincontrol.php sql injection
A vulnerability was found in code-projects Wazifa System 1.0. It has been classified as critical. This affects an unknown part of the file /controllers/logincontrol.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10699?
CVE-2024-10699 is classified as a critical vulnerability.
What part of Wazifa System is affected by CVE-2024-10699?
CVE-2024-10699 affects the /controllers/logincontrol.php file in Wazifa System 1.0.
What type of attack can be performed due to CVE-2024-10699?
CVE-2024-10699 allows for remote SQL injection attacks through manipulation of the username argument.
Is Wazifa System the only software affected by CVE-2024-10699?
Yes, CVE-2024-10699 specifically affects Wazifa System version 1.0.
How do I fix CVE-2024-10699?
To fix CVE-2024-10699, it is recommended to sanitize and validate user inputs to prevent SQL injection.