CVE-2024-12999
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 29, 2024
Updated: Feb 18, 2025
CWE ID 74
CWE ID 89
Summary
CVE-2024-12999 is a newly disclosed critical vulnerability affecting the PHPGurukul Small CRM 1.0 system. The issue lies in the unknown code of the file /admin/edit-user.php, making it susceptible to SQL injection attacks. By manipulating the id argument, an attacker can gain unauthorized access remotely. Public disclosure of the exploit heightens the risk of potential attacks. Organizations using this CRM are urged to apply patches or updates as soon as possible to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Phpgurukul Small Crm