CVE-2024-10998
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 8, 2024
Updated: Nov 13, 2024
CWE ID 89
CWE ID 74
Summary
CVE-2024-10998 is a critical vulnerability affecting the 1000 Projects Bookstore Management System version 1.0. The issue lies in the processing of the file /admin/process_category_add.php, where an sql injection vulnerability is present. By manipulating the argument cat, an attacker can inject malicious sql commands, allowing remote access to sensitive data or even system takeover. The exploit for this vulnerability has been disclosed to the public, increasing the risk of attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.