CVE-2024-9817
CVSS 3.1 Score 8.8 of 10 (high)
Attack Complexity low
Confidentiality high
Integrity high
Availability high
Privileges Required low
Scope unchanged
Details
Published Oct 10, 2024
Updated: Oct 17, 2024
CWE ID 89
Summary
CVE-2024-9817 is a critical vulnerability affecting the Blood Bank System 1.0 by code-projects. The issue lies in an unknown part of the /update.php file, allowing for sql injection through the manipulation of argument names. This vulnerability can be exploited remotely, meaning an attacker does not need to have local access to initiate the attack. The exploit for this vulnerability has been disclosed to the public, increasing the risk of potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share