CVE-2024-11074: itsourcecode Tailoring Management System incadd.php sql injection
A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. This vulnerability affects unknown code of the file /incadd.php. The manipulation of the argument inccat/desc/date/amount leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "inccat" to be affected. But it must be assumed "desc", "date", and "amount" are affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11074?
CVE-2024-11074 is classified as a critical vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2024-11074?
To fix CVE-2024-11074, it is recommended to sanitize input parameters and implement prepared statements to prevent SQL injection.
What type of vulnerability is CVE-2024-11074?
CVE-2024-11074 is an SQL injection vulnerability affecting the Tailoring Management System 1.0.
Can CVE-2024-11074 be exploited remotely?
Yes, CVE-2024-11074 can be exploited remotely, allowing attackers to manipulate the application from a distance.
Which software versions are affected by CVE-2024-11074?
CVE-2024-11074 affects version 1.0 of the Angeljudesuarez Tailoring Management System.