CVE-2024-27746: SQL Injection
Published Mar 1, 2024
·Updated
SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component.
Credit
Shubham Pandey
Affected Software
2 affected components
Petrol Pump Management Software Petrol Pump Management Software
Mayurik Petrol Pump Management=1.0
Event History
Mar 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Mar 3, 2024
Exploit Published
via ExploitDB·12:00 AM
Known Exploited
via ExploitDB·12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-27746?
CVE-2024-27746 is classified as a high severity vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2024-27746?
To fix CVE-2024-27746, validate and sanitize all user inputs in the email address parameter of the index.php component.
3
What software is affected by CVE-2024-27746?
CVE-2024-27746 affects Petrol Pump Management Software version 1.0.
4
What type of vulnerability is CVE-2024-27746?
CVE-2024-27746 is an SQL Injection vulnerability that can be exploited via crafted payloads.
5
Can CVE-2024-27746 be exploited remotely?
Yes, CVE-2024-27746 can be exploited remotely if the attacker has access to the input fields in the affected application.