First published: Wed Apr 10 2024(Updated: )
A vulnerability, which was classified as critical, has been found in Campcodes Church Management System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259904.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Church Management System | ||
Church Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3534 is classified as a critical vulnerability due to its potential for remote SQL injection attacks.
To fix CVE-2024-3534, ensure that input validation and parameterized queries are implemented in the login.php file to mitigate SQL injection risks.
CVE-2024-3534 affects Campcodes Church Management System version 1.0.
An attacker can execute a remote SQL injection attack through the manipulation of the password parameter in the login.php functionality.
As of now, there is no specific patch available for CVE-2024-3534, but upgrading to a secured version or applying secure coding practices is recommended.