CVE-2024-9894: code-projects Blood Bank System reset.php sql injection
Published Oct 12, 2024
·Updated
A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file reset.php. The manipulation of the argument useremail leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Blood Bank System Project Blood Bank System=1.0
Event History
Oct 12, 2024
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-9894?
CVE-2024-9894 is classified as a critical vulnerability.
2
How does CVE-2024-9894 exploit SQL injection?
CVE-2024-9894 exploits SQL injection through the manipulation of the useremail argument in the reset.php file.
3
Which version of Blood Bank System is affected by CVE-2024-9894?
The affected version of Blood Bank System is 1.0.
4
Can CVE-2024-9894 be exploited remotely?
Yes, CVE-2024-9894 can be exploited remotely.
5
What file contains the vulnerability CVE-2024-9894?
The vulnerability CVE-2024-9894 is found in the reset.php file.