CVE-2024-33958: SQL injection in Janobe E-Negosyo System
Published Aug 6, 2024
·Updated
SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'phonenumber' in '/passwordrecover.php' parameter.
Affected Software
1 affected component
Janobe Young Entrepreneur E-negosyo System=1.0
Remediation
Information
There is no reported solution at this time.
Event History
Aug 6, 2024
CVE Published
via MITRE·11:04 AM
Data Sourced
via MITRE·11:04 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33958?
CVE-2024-33958 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2024-33958?
To fix CVE-2024-33958, update the E-Negosyo System to a patched version provided by the vendor.
3
What systems are affected by CVE-2024-33958?
CVE-2024-33958 affects the E-Negosyo System version 1.0.
4
What kind of attack is possible with CVE-2024-33958?
An attacker can exploit CVE-2024-33958 to execute SQL queries that retrieve sensitive information from the database.
5
What information can be retrieved through CVE-2024-33958?
An attacker can potentially retrieve all the information stored in the 'phonenumber' parameter via the '/passwordrecover.php' file.