First published: Tue Dec 31 2024(Updated: )
A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add-customer-services.php of the component Customer Detail Handler. The manipulation of the argument sids[] leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
1000projects Beauty Parlour Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13072 has been rated as critical.
CVE-2024-13072 affects the /admin/add-customer-services.php file in the Customer Detail Handler component.
CVE-2024-13072 affects version 1.0 of the 1000 Projects Beauty Parlour Management System.
To mitigate the risks of CVE-2024-13072, it is recommended to apply security patches or upgrade to a secure version if available.
An attacker could potentially exploit CVE-2024-13072 to manipulate customer service details and compromise the application.