CVE-2024-12792: Codezips E-Commerce Site newadmin.php sql injection
Published Dec 19, 2024
·Updated
A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file newadmin.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Codezips E-Commerce Site=1.0
Event History
Dec 19, 2024
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12792?
CVE-2024-12792 is classified as a critical vulnerability.
2
How does CVE-2024-12792 allow an attack?
CVE-2024-12792 allows SQL injection via the manipulation of the email argument in newadmin.php.
3
Can CVE-2024-12792 be exploited remotely?
Yes, CVE-2024-12792 can be exploited remotely.
4
Which version of Codezips E-Commerce Site is affected by CVE-2024-12792?
CVE-2024-12792 affects Codezips E-Commerce Site version 1.0.
5
What is the impact of CVE-2024-12792 on the system?
CVE-2024-12792 can lead to unauthorized access to the database and potential data breaches.