First published: Wed Feb 28 2024(Updated: )
SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php endpoint.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Visitor Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22983 is classified as a high severity SQL injection vulnerability.
CVE-2024-22983 allows remote attackers to escalate privileges through the name parameter in myform.php.
CVE-2024-22983 affects Projectworlds Visitor Management System in PHP v.1.0.
To address CVE-2024-22983, sanitize user inputs and implement prepared statements to prevent SQL injection.
Yes, CVE-2024-22983 can be exploited remotely, allowing attackers to escalate privileges.