CVE-2024-50972: SQL Injection
Published Nov 13, 2024
·Updated
A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrowid parameter.
Affected Software
1 affected component
Angeljudesuarez Construction Management System=1.0
Event History
Nov 13, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-50972?
CVE-2024-50972 has a high severity rating due to its potential to allow remote SQL injection attacks.
2
How do I fix CVE-2024-50972?
To fix CVE-2024-50972, validate and sanitize the borrow_id parameter to prevent SQL injection.
3
What systems are affected by CVE-2024-50972?
CVE-2024-50972 affects version 1.0 of the Itsourcecode Construction Management System.
4
What are the potential impacts of exploiting CVE-2024-50972?
Exploiting CVE-2024-50972 could allow attackers to execute arbitrary SQL commands, leading to data compromise.
5
Are there any known exploits for CVE-2024-50972?
Yes, there are known exploit methods for CVE-2024-50972 that take advantage of the SQL injection vulnerability.