CVE-2024-1924: CodeAstro Membership Management System get_membership_amount.php sql injection
A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the file /getmembershipamount.php. The manipulation of the argument membershipTypeId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254859.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1924?
CVE-2024-1924 is classified as critical due to its potential for SQL injection.
How do I fix CVE-2024-1924?
To fix CVE-2024-1924, implement input validation and use parameterized queries to prevent SQL injection.
What components are affected by CVE-2024-1924?
CVE-2024-1924 affects the CodeAstro Membership Management System version 1.0, specifically the /get_membership_amount.php file.
What type of vulnerability is CVE-2024-1924?
CVE-2024-1924 is an SQL injection vulnerability that exploits the membershipTypeId argument.
Can CVE-2024-1924 be exploited remotely?
Yes, CVE-2024-1924 can potentially be exploited remotely by manipulating requests to the vulnerable endpoint.