CVE-2024-13002: 1000 Projects Bookstore Management System order_process.php sql injection
A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /orderprocess.php. The manipulation of the argument fnm leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13002?
CVE-2024-13002 has been declared as critical.
What software is affected by CVE-2024-13002?
CVE-2024-13002 affects the 1000 Projects Bookstore Management System version 1.0.
What type of vulnerability is CVE-2024-13002?
CVE-2024-13002 is a SQL injection vulnerability caused by improper handling of the 'fnm' argument in the '/order_process.php' file.
How can I mitigate CVE-2024-13002?
To mitigate CVE-2024-13002, it is recommended to sanitize and validate user inputs in the affected file.
What are the potential impacts of CVE-2024-13002?
Exploitation of CVE-2024-13002 may allow attackers to execute arbitrary SQL queries, leading to unauthorized data access or modification.