CVE-2024-12784

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Dec 19, 2024
CWE ID 89
CWE ID 74

Summary

CVE-2024-12784 is a critical vulnerability affecting the Vehicle Management System 1.0. An unknown function in the file editbill.php contains a SQL injection flaw. By manipulating the argument id, an attacker can inject malicious SQL queries, potentially leading to unauthorized data access or modification. The vulnerability can be exploited remotely, increasing the risk to affected systems. Public disclosure of the exploit heightens the urgency for organizations using this software to apply the necessary patches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share