CVE-2024-11998: code-projects Farmacia visualizer-forneccedor.chp sql injection
Published Nov 30, 2024
·Updated
A vulnerability was found in code-projects Farmacia 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /visualizer-forneccedor.chp. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Farmacia Project Farmacia=1.0
Event History
Nov 30, 2024
CVE Published
via MITRE·09:31 AM
Data Sourced
via MITRE·09:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-11998?
CVE-2024-11998 has been declared as critical.
2
How does CVE-2024-11998 affect the system?
CVE-2024-11998 allows for SQL injection through manipulation of the 'id' argument in the file /visualizer-forneccedor.chp.
3
Can CVE-2024-11998 be exploited remotely?
Yes, CVE-2024-11998 can be exploited remotely.
4
What software is affected by CVE-2024-11998?
CVE-2024-11998 affects Farmacia version 1.0.
5
How do I fix CVE-2024-11998?
To fix CVE-2024-11998, you should sanitize input and implement parameterized queries to prevent SQL injection.