CVE-2024-13006

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Dec 29, 2024
Updated: Mar 3, 2025
CWE ID 89
CWE ID 74

Summary

CVE-2024-13006: A critical vulnerability has been identified in version 1.0 of the 1000 Projects Human Resource Management System. This issue arises from improper handling of user input in the file /employeeview.php, resulting in SQL injection. An attacker can exploit this remotely and manipulate the system, potentially gaining unauthorized access to sensitive data. The exploit for this vulnerability has been made public.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share