CVE-2024-9295

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Sep 28, 2024
Updated: Oct 1, 2024
CWE ID 89

Summary

CVE-2024-9295 is a critical vulnerability affecting the SourceCodester Advocate Office Management System version 1.0. This issue arises from a processing flaw in the /control/login.php file, which can be exploited through SQL injection. Manipulation of the username argument allows an attacker to inject malicious SQL code, potentially gaining unauthorized access to the system. The vulnerability can be exploited remotely, making it a significant security risk. The existence and exploit details of this vulnerability have been made public, increasing the urgency for affected organizations to apply the necessary patches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share