CVE-2024-12926

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Dec 25, 2024
Updated: Dec 27, 2024
CWE ID 89
CWE ID 74

Summary

CVE-2024-12926 is a critical vulnerability identified in the Codezips Project Management System 1.0. This issue affects an unspecified functionality within the file /pages/forms/advanced.php, allowing for sql injection attacks. The manipulation of argument names can be exploited remotely, potentially putting other parameters at risk as well. The vulnerability has been publicly disclosed, increasing the threat of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Project Management System

Affected Vendors

  • Codezips