First published: Sun Sep 22 2024(Updated: )
A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument date leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions sid as affected paramater which is incorrect.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
code-projects Restaurant Reservation System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9085 is rated as critical due to the potential for SQL injection vulnerabilities.
CVE-2024-9085 affects the index.php file of the Restaurant Reservation System, allowing remote SQL injection through manipulated date parameters.
To fix CVE-2024-9085, it is recommended to validate and sanitize user input in the index.php file to prevent SQL injection.
Yes, CVE-2024-9085 can be exploited remotely, making it crucial for users of the affected software to address this vulnerability promptly.
CVE-2024-9085 specifically affects version 1.0 of the Restaurant Reservation System.