CVE-2024-25217: SQL Injection
Published Feb 14, 2024
·Updated
Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/viewproduct.
Affected Software
1 affected component
oretnom23 Online Medicine Ordering System=1.0
Event History
Feb 14, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25217?
CVE-2024-25217 has a high severity rating due to its SQL injection vulnerability that can be exploited by unauthorized users.
2
How do I fix CVE-2024-25217?
To fix CVE-2024-25217, validate and sanitize user inputs to prevent SQL injection in the 'id' parameter.
3
What systems are affected by CVE-2024-25217?
CVE-2024-25217 affects Online Medicine Ordering System version 1.0.
4
What type of vulnerability is CVE-2024-25217?
CVE-2024-25217 is a SQL injection vulnerability that allows attackers to manipulate database queries.
5
Can CVE-2024-25217 be exploited without authentication?
Yes, CVE-2024-25217 can be exploited without authentication, making it particularly dangerous.