CVE-2024-11970: code-projects Concert Ticket Ordering System tour(cor).php sql injection
A vulnerability classified as critical has been found in code-projects Concert Ticket Ordering System 1.0. Affected is an unknown function of the file /tour(cor).php. The manipulation of the argument mai leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11970?
CVE-2024-11970 is classified as a critical vulnerability due to the potential for remote SQL injection.
How do I fix CVE-2024-11970?
To fix CVE-2024-11970, sanitize and validate all user inputs, especially the 'mai' argument in /tour(cor).php.
What systems are affected by CVE-2024-11970?
CVE-2024-11970 affects version 1.0 of the Anisha Concert Ticket Ordering System.
Can CVE-2024-11970 be exploited remotely?
Yes, CVE-2024-11970 can be exploited remotely through SQL injection.
What type of vulnerability is CVE-2024-11970?
CVE-2024-11970 is an SQL injection vulnerability that allows attackers to manipulate database queries.