CVE-2024-55509: SQL Injection
Published Dec 20, 2024
·Updated
SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component.
Affected Software
2 affected components
Codeastro Complaint Management System
Codeastro Complaint Management System=1.0
Event History
Dec 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-55509?
CVE-2024-55509 is considered to be a high severity SQL injection vulnerability.
2
What does CVE-2024-55509 allow an attacker to do?
CVE-2024-55509 allows a remote attacker to execute arbitrary code and escalate privileges.
3
Which component of CodeAstro Complaint Management System is affected by CVE-2024-55509?
The delete.php component of the CodeAstro Complaint Management System is affected by CVE-2024-55509.
4
How do I fix CVE-2024-55509?
To fix CVE-2024-55509, validate and sanitize all user inputs, particularly the 'id' parameter in delete.php.
5
What versions of the Complaint Management System are affected by CVE-2024-55509?
CVE-2024-55509 affects version 1.0 of the CodeAstro Complaint Management System.