CVE-2024-10735: Project Worlds Life Insurance Management System editNominee.php sql injection
A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /editNominee.php. The manipulation of the argument nomineeid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10735?
CVE-2024-10735 has been declared as critical due to its potential for SQL injection.
How does CVE-2024-10735 affect the Life Insurance Management System?
CVE-2024-10735 affects the /editNominee.php file, allowing attackers to manipulate the nominee_id argument.
How do I fix CVE-2024-10735?
To fix CVE-2024-10735, validate and sanitize user inputs in the /editNominee.php file to prevent SQL injection.
Who is affected by CVE-2024-10735?
CVE-2024-10735 affects users of Project Worlds Life Insurance Management System version 1.0.
What exploit can be performed using CVE-2024-10735?
Exploiting CVE-2024-10735 can allow an attacker to perform SQL injection attacks on the application.