CVE-2024-11646: 1000 Projects Beauty Parlour Management System edit-services.php sql injection
A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit-services.php. The manipulation of the argument sername leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11646?
CVE-2024-11646 is classified as a critical vulnerability.
What is affected by CVE-2024-11646?
CVE-2024-11646 affects version 1.0 of the 1000 Projects Beauty Parlour Management System.
What kind of vulnerability is CVE-2024-11646?
CVE-2024-11646 is an SQL injection vulnerability found in the /admin/edit-services.php file.
How can CVE-2024-11646 be exploited?
CVE-2024-11646 can be exploited by manipulating the 'sername' argument in the vulnerable functionality.
How do I fix CVE-2024-11646?
To fix CVE-2024-11646, update to a patched version of the 1000 Projects Beauty Parlour Management System as soon as it becomes available.