CVE-2024-12007: code-projects Farmacia visualizar-produto.php sql injection
A vulnerability, which was classified as critical, was found in code-projects Farmacia 1.0. This affects an unknown part of the file /visualizar-produto.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12007?
CVE-2024-12007 is classified as a critical severity vulnerability.
How does CVE-2024-12007 allow an attacker to exploit the system?
CVE-2024-12007 allows an attacker to perform SQL injection by manipulating the 'id' argument in the /visualizar-produto.php file.
Which software versions are affected by CVE-2024-12007?
CVE-2024-12007 affects version 1.0 of code-projects Farmacia.
How can I mitigate the risk associated with CVE-2024-12007?
To mitigate the risk of CVE-2024-12007, you should sanitize and validate all user inputs to prevent SQL injection vulnerabilities.
Can CVE-2024-12007 be exploited remotely?
Yes, CVE-2024-12007 can be exploited remotely.