CVE-2024-13005: 1000 Projects Attendance Tracking Management System attendance_action.php sql injection
A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/attendanceaction.php. The manipulation of the argument attendanceid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13005?
CVE-2024-13005 is classified as a critical vulnerability.
How does CVE-2024-13005 impact the Attendance Tracking Management System?
CVE-2024-13005 affects an SQL injection vulnerability in the /admin/attendance_action.php file.
What are the consequences of exploiting CVE-2024-13005?
Exploiting CVE-2024-13005 can lead to unauthorized access to sensitive data within the system.
How can I fix CVE-2024-13005?
To fix CVE-2024-13005, validate and sanitize user inputs, particularly the attendance_id parameter.
Which versions of the Attendance Tracking Management System are vulnerable to CVE-2024-13005?
CVE-2024-13005 affects version 1.0 of the 1000 Projects Attendance Tracking Management System.