CVE-2024-12784: itsourcecode Vehicle Management System editbill.php sql injection
Published Dec 19, 2024
·Updated
A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been classified as critical. Affected is an unknown function of the file editbill.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
itsourcecode Vehicle Management System
Admerc Vehicle Management System=1.0
Event History
Dec 19, 2024
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 4, 57087
Event
via NVD·02:36 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-12784?
CVE-2024-12784 has been classified as critical.
2
How can CVE-2024-12784 be exploited?
CVE-2024-12784 can be exploited through SQL injection via the id argument in editbill.php.
3
Who is affected by CVE-2024-12784?
CVE-2024-12784 affects users of itsourcecode Vehicle Management System version 1.0.
4
How do I fix CVE-2024-12784?
To fix CVE-2024-12784, validate and sanitize input data in the editbill.php file to prevent SQL injection.
5
Is remote exploitation possible for CVE-2024-12784?
Yes, CVE-2024-12784 can be attacked remotely.