CVE-2024-12960: 1000 Projects Portfolio Management System MCA update_edu_details.php sql injection
A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0. This issue affects some unknown processing of the file /updateedudetails.php. The manipulation of the argument q leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12960?
CVE-2024-12960 is classified as a critical vulnerability.
How do I fix CVE-2024-12960?
To fix CVE-2024-12960, it is recommended to sanitize user input and implement prepared statements to prevent SQL injection.
What type of vulnerability is CVE-2024-12960?
CVE-2024-12960 is an SQL injection vulnerability affecting the 1000 Projects Portfolio Management System MCA.
Which file is affected by CVE-2024-12960?
CVE-2024-12960 affects the processing of the file /update_edu_details.php.
What impact does CVE-2024-12960 have?
CVE-2024-12960 allows attackers to manipulate SQL queries, potentially leading to unauthorized data access.