CVE-2024-11256: 1000 Projects Portfolio Management System MCA login.php sql injection
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue affects some unknown processing of the file /login.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11256?
CVE-2024-11256 is classified as a critical vulnerability.
How does CVE-2024-11256 affect the 1000 Projects Portfolio Management System MCA?
CVE-2024-11256 affects the /login.php file leading to SQL injection through the username argument.
Can CVE-2024-11256 be exploited remotely?
Yes, the vulnerability can be initiated remotely by an attacker.
What version of the software is vulnerable to CVE-2024-11256?
The vulnerability affects version 1.0 of the 1000 Projects Portfolio Management System MCA.
How do I fix CVE-2024-11256?
To fix CVE-2024-11256, it is recommended to secure the input validation for the username parameter to prevent SQL injection.