CVE-2024-13035: code-projects Chat System update_user.php sql injection
Published Dec 30, 2024
·Updated
A vulnerability has been found in code-projects Chat System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/updateuser.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Code-projects Chat System=1.0
Event History
Dec 30, 2024
CVE Published
via MITRE·02:31 AM
Data Sourced
via MITRE·02:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13035?
CVE-2024-13035 is classified as a critical vulnerability.
2
How does CVE-2024-13035 affect the Chat System software?
CVE-2024-13035 allows for SQL injection due to improper handling of user input in /admin/update_user.php.
3
Can CVE-2024-13035 be exploited remotely?
Yes, the exploit for CVE-2024-13035 can be initiated remotely.
4
What versions of the Chat System are affected by CVE-2024-13035?
CVE-2024-13035 affects version 1.0 of the Chat System.
5
How do I fix the vulnerability CVE-2024-13035?
To fix CVE-2024-13035, you should sanitize inputs in /admin/update_user.php and apply all security patches from the vendor.