CVE-2024-10408 Information
Nov 01, 2024
cve
Description
A vulnerability has been found in code-projects Blood Bank Management up to 1.0 and classified as critical. This vulnerability affects unknown code of the file /abs.php. The manipulation of the argument search leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://vuldb.com/?id.281938 https://vuldb.com/?ctiid.281938 https://vuldb.com/?submit.431491 https://gist.github.com/higordiego/46090516ba1b13fe3d2607ab4c0114f1 https://code-projects.org/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: