CVE-2024-6653

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Jul 11, 2024
CWE ID 89

Summary

CVE-2024-6653 is a critical vulnerability affecting the Simple Task List 1.0 component, specifically the loginForm.php file of the Login component. This issue enables attackers to inject SQL code by manipulating the username argument, which can be done remotely. The exploit for this vulnerability has been disclosed to the public, increasing the risk of potential attacks. No detailed copies of the source text are used in this summary, but it is important to note that this SQL injection vulnerability could have serious consequences if left unpatched.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share