CVE-2024-11074

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 11, 2024
Updated: Nov 14, 2024
CWE ID 89
CWE ID 74

Summary

CVE-2024-11074 is a newly disclosed critical vulnerability in the Tailoring Management System 1.0. The issue lies in the manipulation of the arguments "inccat/desc/date/amount" in the file /incadd.php, which leads to SQL injection. This vulnerability can be exploited remotely, and the attacker can take advantage of it to gain unauthorized access to the system. The exploit for this vulnerability has been made public, increasing the risk of widespread exploitation. Initial research suggests that the parameters "inccat" may be affected, but it is assumed that "desc," "date," and "amount" are also susceptible to manipulation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share