CVE-2024-7936
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Aug 20, 2024
CWE ID 89
Summary
CVE-2024-7936 is a newly disclosed critical vulnerability in the Project Expense Monitoring System 1.0. The issue lies within the transferred_report.php file and is triggered by the manipulation of the start, end, and employee arguments. This vulnerability allows for sql injection attacks, which can be initiated remotely. The exploit for this vulnerability has been made public, heightening the risk for potential exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share