CVE-2024-12949
CVSS 2.0 Score 6.5 of 10 (medium)
Details
Published Dec 26, 2024
Updated: Dec 27, 2024
CWE ID 89
CWE ID 74
Summary
CVE-2024-12949 is a newly disclosed critical vulnerability affecting the Travel Management System 1.0 of code-projects. This issue resides in unknown code within the /package.php file and can be exploited through manipulation of the 'subcatid' argument, allowing an attacker to inject SQL queries remotely. The consequences of this vulnerability can be severe, and since the exploit has been made public, it is urged that users take immediate actions to patch or mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- TRAVEL MANAGEMENT SYSTEM
Affected Vendors
- Code Projects