CVE-2024-12927: 1000 Projects Attendance Tracking Management System check_faculty_login.php sql injection
A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected by this issue is some unknown functionality of the file /faculty/checkfacultylogin.php. The manipulation of the argument facultyemailid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12927?
CVE-2024-12927 has been classified as a critical vulnerability.
How do I fix CVE-2024-12927?
To fix CVE-2024-12927, it's essential to update the Attendance Tracking Management System to a patched version that addresses this vulnerability.
What component is affected in CVE-2024-12927?
CVE-2024-12927 affects the functionality of the file /faculty/check_faculty_login.php in the Attendance Tracking Management System.
What exploitation method is used in CVE-2024-12927?
CVE-2024-12927 can be exploited by manipulating the argument faculty_emailid in the affected file.
Who is the vendor for CVE-2024-12927?
The vendor for CVE-2024-12927 is 1000 Projects, the creator of the Attendance Tracking Management System.