CVE-2024-9986

NVD Published Date: October 15, 2024 at 01:15 PM
NVD Last Modified: October 21, 2024 at 01:07 PM
Download Patch
Vulnerability ID
CVE-2024-9986
Severity
CRITICAL
Severity Score
9.8
Summary
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file member_register.php. The manipulation of the argument fullname/username/password/email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "password" to be affected. But it must be assumed that other parameters are affected as well.
Mitigation and Patches
-
Metasploit Payload
-
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE ID
CWE-89

Recent Publish

KB5044321

KB5044342

CVE-2024-9139

CVE-2024-43701

KB5044343

KB5044356

See More ...

See SecOps Solution
in action

Schedule Demo