First published: Thu Dec 26 2024(Updated: )
A vulnerability was found in code-projects Travel Management System 1.0. It has been classified as critical. This affects an unknown part of the file /detail.php. The manipulation of the argument pid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Travel Management System | ||
Travel Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12948 has been classified as critical due to its potential for remote SQL injection.
To fix CVE-2024-12948, it is recommended to validate and sanitize all user inputs in the detail.php file where the vulnerability exists.
CVE-2024-12948 is an SQL injection vulnerability that can be exploited remotely by manipulating the 'pid' parameter.
CVE-2024-12948 affects the code-projects Travel Management System version 1.0.
Yes, CVE-2024-12948 can be exploited remotely by attackers targeting the vulnerable detail.php file.