CVE-2024-24495: SQL Injection
Published Feb 8, 2024
·Updated
SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.
Credit
Yevhenii Butenko
Affected Software
1 affected component
Remyandrade Daily Habit Tracker=1.0
Event History
Feb 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Apr 2, 2024
Exploit Published
via ExploitDB·12:00 AM
Known Exploited
via ExploitDB·12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-24495?
CVE-2024-24495 is classified as a high severity SQL Injection vulnerability.
2
How do I fix CVE-2024-24495?
To fix CVE-2024-24495, you should sanitize and validate all user inputs in delete-tracker.php to prevent SQL injection.
3
Who is affected by CVE-2024-24495?
CVE-2024-24495 affects users of Daily Habit Tracker version 1.0.
4
What kind of attack can be executed using CVE-2024-24495?
CVE-2024-24495 allows attackers to execute arbitrary code via crafted GET requests.
5
Is CVE-2024-24495 exploitable remotely?
Yes, CVE-2024-24495 is a remotely exploitable vulnerability.