First published: Thu Oct 10 2024(Updated: )
A vulnerability was found in LyLme_spage 1.9.5. It has been classified as critical. Affected is an unknown function of the file /admin/sou.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
LyLme Spage | =1.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9790 has been classified as critical.
CVE-2024-9790 is an SQL injection vulnerability.
To fix CVE-2024-9790, validate and sanitize input used in the /admin/sou.php file.
Yes, CVE-2024-9790 can be exploited remotely.
CVE-2024-9790 affects LyLme_spage version 1.9.5.