CVE-2024-9085: code-projects Restaurant Reservation System index.php sql injection
A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument date leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions sid as affected paramater which is incorrect.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9085?
CVE-2024-9085 is rated as critical due to the potential for SQL injection vulnerabilities.
How does CVE-2024-9085 affect the Restaurant Reservation System?
CVE-2024-9085 affects the index.php file of the Restaurant Reservation System, allowing remote SQL injection through manipulated date parameters.
What action should be taken to fix CVE-2024-9085?
To fix CVE-2024-9085, it is recommended to validate and sanitize user input in the index.php file to prevent SQL injection.
Can CVE-2024-9085 be exploited remotely?
Yes, CVE-2024-9085 can be exploited remotely, making it crucial for users of the affected software to address this vulnerability promptly.
Which version of the Restaurant Reservation System is affected by CVE-2024-9085?
CVE-2024-9085 specifically affects version 1.0 of the Restaurant Reservation System.