CVE-2024-12949

CVSS 2.0 Score 6.5 of 10 (medium)

Details

Published Dec 26, 2024
Updated: Dec 27, 2024
CWE ID 89
CWE ID 74

Summary

CVE-2024-12949 is a newly disclosed critical vulnerability affecting the Travel Management System 1.0 of code-projects. This issue resides in unknown code within the /package.php file and can be exploited through manipulation of the 'subcatid' argument, allowing an attacker to inject SQL queries remotely. The consequences of this vulnerability can be severe, and since the exploit has been made public, it is urged that users take immediate actions to patch or mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • TRAVEL MANAGEMENT SYSTEM

Affected Vendors

  • Code Projects