CVE-2024-12884: Codezips E-Commerce Website login.php sql injection
A vulnerability was found in Codezips E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12884?
CVE-2024-12884 has been rated as critical due to its potential for remote SQL injection.
How do I fix CVE-2024-12884?
To fix CVE-2024-12884, ensure proper input validation and use prepared statements for SQL queries in the /login.php file.
What type of vulnerability is CVE-2024-12884?
CVE-2024-12884 is a SQL injection vulnerability that affects the login functionality.
Can CVE-2024-12884 be exploited remotely?
Yes, CVE-2024-12884 can be exploited remotely by manipulating the email argument.
Which software version is affected by CVE-2024-12884?
CVE-2024-12884 affects version 1.0 of Codezips E-Commerce Website.