CVE-2024-44812: SQL Injection
Published Oct 22, 2024
·Updated
SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password parameters in the /admin.index.php component.
Affected Software
1 affected component
Janobe Online Complaint Site=1.0
Event History
Oct 22, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-44812?
CVE-2024-44812 is classified as a high severity SQL Injection vulnerability.
2
How do I fix CVE-2024-44812?
To fix CVE-2024-44812, update the Online Complaint Site to the latest version or sanitize user inputs in the affected parameters.
3
What are the potential impacts of CVE-2024-44812?
CVE-2024-44812 allows remote attackers to escalate privileges, potentially leading to unauthorized access to sensitive administrative functions.
4
Which version of Online Complaint Site is affected by CVE-2024-44812?
CVE-2024-44812 affects Online Complaint Site version 1.0.
5
Can CVE-2024-44812 be exploited remotely?
Yes, CVE-2024-44812 can be exploited remotely by an attacker targeting the affected /admin.index.php component.