CVE-2024-12946: 1000 Projects Attendance Tracking Management System admin_action.php sql injection
A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System 1.0. This issue affects some unknown processing of the file /admin/adminaction.php. The manipulation of the argument adminusername leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12946?
CVE-2024-12946 is classified as a critical vulnerability.
What type of vulnerability is CVE-2024-12946?
CVE-2024-12946 is an SQL injection vulnerability found in the 1000 Projects Attendance Tracking Management System.
How do I fix CVE-2024-12946?
To fix CVE-2024-12946, sanitize and validate user input in the admin_user_name parameter of the /admin/admin_action.php file.
Which software is affected by CVE-2024-12946?
CVE-2024-12946 affects version 1.0 of the 1000 Projects Attendance Tracking Management System.
What is the impact of CVE-2024-12946?
CVE-2024-12946 can lead to unauthorized database access and manipulation through SQL injection.