CVE-2024-25215
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 14, 2024
Updated: Feb 15, 2024
CWE ID 89
Summary
CVE-2024-25215 is a newly disclosed SQL injection vulnerability affecting Employee Management System version 1.0. This issue can be exploited by malicious actors via the pwd parameter located in the /aprocess.php file. Successful exploitation of this vulnerability allows attackers to execute unauthorized SQL statements, potentially leading to unintended data access or modification. The vulnerability poses a significant risk to organizations using this outdated system and urges immediate patching or mitigation measures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Sherlock Company