First published: Tue Apr 09 2024(Updated: )
A vulnerability classified as critical was found in Campcodes Online Event Management System 1.0. This vulnerability affects unknown code of the file /views/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259894 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Campcodes Online Event Management System | ||
Campcodes Online Event Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3523 is classified as critical due to its potential for SQL injection and remote exploitation.
To fix CVE-2024-3523, sanitize and validate input parameters and update the Campcodes Online Event Management System to a patched version.
CVE-2024-3523 is an SQL injection vulnerability that can be exploited remotely through the manipulation of input arguments.
CVE-2024-3523 affects the file /views/index.php within the Campcodes Online Event Management System.
Yes, CVE-2024-3523 can be exploited remotely, making authentication unnecessary for the attack.