CVE-2024-0272
Kashipara
CVE-2024-0272 is a critical SQL Injection vulnerability found in Kashipara Food Management System up to version 1.0, affecting the addmaterialsubmit.php file. By manipulating the 'material_name' argument, attackers can inject malicious SQL code. This remote exploit is publicly available, making it easily exploitable.
The vulnerability allows attackers to potentially read, modify, or delete sensitive data from the database. While the CVSS score is 6.5, the SOCRadar Vulnerability Risk Score (SVRS) is 61, indicating a moderate but noteworthy risk. Although not classified as critical (SVRS > 80), immediate patching is recommended to prevent potential data breaches and maintain application security. This issue highlights the importance of input sanitization and secure coding practices.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.