First published: Thu Dec 19 2024(Updated: )
A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file sendmail.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
itsourcecode Vehicle Management System | ||
Angeljudesuarez Vehicle Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12785 is classified as critical due to its potential for widespread impact through SQL injection.
CVE-2024-12785 affects the Vehicle Management System by allowing an attacker to manipulate the id argument in sendmail.php to execute SQL injection attacks.
CVE-2024-12785 impacts version 1.0 of the Vehicle Management System developed by itsourcecode.
To mitigate CVE-2024-12785, developers should sanitize inputs and implement prepared statements to prevent SQL injection.
Yes, CVE-2024-12785 can be exploited remotely, making it critical for users to address the vulnerability promptly.