CVE-2024-3697
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-3697 is a newly disclosed critical vulnerability affecting the Campcodes House Rental Management System 1.0. The vulnerability lies in an unknown function of the file manage_tenant.php and can be exploited through SQL injection. By manipulating the argument id, an attacker can inject malicious SQL commands into the system. This attack can be launched remotely, increasing the risk to affected organizations. The exploit for this vulnerability has already been made public, heightening the urgency for affected organizations to apply the necessary patches or updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.