CVE-2024-7195: itsourcecode Society Management System check_admin.php sql injection
A vulnerability was found in itsourcecode Society Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/checkadmin.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272616.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7195?
CVE-2024-7195 is classified as a critical vulnerability.
How does the exploit for CVE-2024-7195 work?
The exploit for CVE-2024-7195 works by manipulating the username argument in the /admin/check_admin.php file to perform SQL injection.
What systems are affected by CVE-2024-7195?
CVE-2024-7195 affects the Society Management System version 1.0 developed by Angeljudesuarez.
How do I mitigate the risks of CVE-2024-7195?
To mitigate the risks of CVE-2024-7195, it is recommended to apply input validation and sanitize user inputs in the affected system.
Is there a patch available for CVE-2024-7195?
As of now, there is no specific patch available for CVE-2024-7195, so upgrading or implementing security controls is advised.