CVE-2024-55496
CVE-2024-55496 is a SQL injection vulnerability found in the 1000projects Bookstore Management System. Specifically, the vulnerability lies within the add_company.php file, where manipulating the delete parameter allows for arbitrary SQL commands to be executed. With an SVRS of 30, the risk is moderate, and while not critical, it requires attention to prevent potential exploitation.
This vulnerability allows attackers to potentially compromise the database by injecting malicious SQL code. This can lead to data breaches, data manipulation, or even complete system takeover. Although the CVSS score is 0, the presence of a SQL injection flaw means malicious actors could exploit this to gain unauthorized access to sensitive data. Immediate patching or mitigation is advised to reduce the attack surface and protect the application. Given that this CVE has been tagged "In The Wild", the active exploitation of this vulnerability has been observed.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.