First published: Fri Nov 15 2024(Updated: )
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue affects some unknown processing of the file /login.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
1000 Projects Portfolio Management System MCA | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-11256 is classified as a critical vulnerability.
CVE-2024-11256 affects the /login.php file leading to SQL injection through the username argument.
Yes, the vulnerability can be initiated remotely by an attacker.
The vulnerability affects version 1.0 of the 1000 Projects Portfolio Management System MCA.
To fix CVE-2024-11256, it is recommended to secure the input validation for the username parameter to prevent SQL injection.