CVE-2024-12961: 1000 Projects Portfolio Management System MCA update_ach_details.php sql injection
A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. Affected is an unknown function of the file /updateachdetails.php. The manipulation of the argument q leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12961?
CVE-2024-12961 is classified as a critical vulnerability.
What type of vulnerability is CVE-2024-12961?
CVE-2024-12961 is an SQL injection vulnerability found in the 1000 Projects Portfolio Management System MCA.
How do I fix CVE-2024-12961?
To fix CVE-2024-12961, sanitize and validate all user inputs to prevent SQL injection.
What file is affected by CVE-2024-12961?
CVE-2024-12961 affects the file /update_ach_details.php in the 1000 Projects Portfolio Management System MCA.
Can CVE-2024-12961 be exploited remotely?
Yes, CVE-2024-12961 can be exploited remotely due to its nature as an SQL injection vulnerability.