CVE-2024-12950

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Dec 26, 2024
CWE ID 74
CWE ID 89

Summary

CVE-2024-12950 is a newly disclosed critical vulnerability affecting the Travel Management System 1.0 by code-projects. The issue lies in the processing of the /subcat.php file, where the catid argument is susceptible to SQL injection. This vulnerability enables remote attackers to manipulate the system's data, potentially resulting in significant data loss or unauthorized access. The exploit for this vulnerability has been made public, increasing the risk for potential attacks. Organizations using this version of the Travel Management System are urged to apply patches or updates as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share