CVE-2024-5517
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published May 30, 2024
CWE ID 89
Summary
CVE-2024-5517 is a newly disclosed critical vulnerability affecting the Online Blood Bank Management System 1.0. The issue lies within an unknown functionality of the file changepwd.php, which can be exploited through sql injection by manipulating the useremail argument. The vulnerability allows remote attacks and the exploit has been made public, increasing the risk of exploitation. This security flaw has been assigned the identifier VDB-266588 by the Vulnerability Database.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share