CVE-2024-12958: 1000 Projects Portfolio Management System MCA update_pro_details.php sql injection
A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. This affects an unknown part of the file /updateprodetails.php. The manipulation of the argument q leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12958?
CVE-2024-12958 is classified as a critical vulnerability.
How does CVE-2024-12958 exploit the system?
CVE-2024-12958 exploits the system through SQL injection via the /update_pro_details.php file.
Which software is affected by CVE-2024-12958?
CVE-2024-12958 affects the 1000 Projects Portfolio Management System MCA version 1.0.
Can CVE-2024-12958 be attacked remotely?
Yes, CVE-2024-12958 allows for remote exploitation of the vulnerability.
How can I mitigate the risks associated with CVE-2024-12958?
Mitigation for CVE-2024-12958 involves securing the input fields against SQL injection and applying software patches provided by the vendor.