CVE-2024-11101: 1000 Projects Beauty Parlour Management System search-invoices.php sql injection
A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/search-invoices.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11101?
The severity of CVE-2024-11101 is classified as critical.
How does CVE-2024-11101 impact the Beauty Parlour Management System?
CVE-2024-11101 allows for SQL injection through the manipulation of the 'searchdata' argument in the /admin/search-invoices.php file.
What versions of the Beauty Parlour Management System are affected by CVE-2024-11101?
CVE-2024-11101 affects version 1.0 of the 1000 Projects Beauty Parlour Management System.
How can I fix CVE-2024-11101?
To fix CVE-2024-11101, input validation and sanitization measures should be implemented to prevent SQL injection in the application.
Where is CVE-2024-11101 located in the Beauty Parlour Management System?
CVE-2024-11101 is located in the /admin/search-invoices.php file.