CVE-2024-1971: Surya2Developer Online Shopping System POST Parameter login.php sql injection
A vulnerability has been found in Surya2Developer Online Shopping System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Parameter Handler. The manipulation of the argument password with the input nochizplz'+or+1%3d1+limit+1%23 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-255127.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1971?
CVE-2024-1971 is classified as a critical vulnerability.
How does CVE-2024-1971 affect the Surya2Developer Online Shopping System?
CVE-2024-1971 affects the login.php component through improper handling of the password parameter.
How do I fix CVE-2024-1971?
To fix CVE-2024-1971, update the Surya2Developer Online Shopping System to the latest version that addresses this vulnerability.
What kind of attacks can be executed due to CVE-2024-1971?
CVE-2024-1971 could allow attackers to exploit SQL injection vulnerabilities potentially leading to unauthorized access.
Is CVE-2024-1971 present in earlier versions of the Surya2Developer Online Shopping System?
CVE-2024-1971 is specifically noted for version 1.0 of the Surya2Developer Online Shopping System.