CVE-2024-46078
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 4, 2024
Updated: Oct 7, 2024
CWE ID 89
Summary
CVE-2024-46078: A vulnerability has been identified in itsourcecode Sports Management System Project 1.0, which allows SQL Injection attacks through the delete_category function found in the file sports_scheduling/player.php. An attacker can exploit this flaw by manipulating the id argument, potentially gaining unauthorized access to sensitive data or causing unintended database modifications. This vulnerability poses a significant risk to organizations using this software, making it crucial to apply the necessary patches as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.