CVE-2024-12950
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Summary
CVE-2024-12950 is a newly disclosed critical vulnerability affecting the Travel Management System 1.0 by code-projects. The issue lies in the processing of the /subcat.php file, where the catid argument is susceptible to SQL injection. This vulnerability enables remote attackers to manipulate the system's data, potentially resulting in significant data loss or unauthorized access. The exploit for this vulnerability has been made public, increasing the risk for potential attacks. Organizations using this version of the Travel Management System are urged to apply patches or updates as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.