CVE-2024-6041
Admerc
CVE-2024-6041 is a critical SQL Injection vulnerability found in itsourcecode Gym Management System 1.0. This flaw allows remote attackers to manipulate the 'id' argument in the 'manage_user.php' file to execute arbitrary SQL commands. While the CVSS score is 8.8 (High), the SOCRadar Vulnerability Risk Score (SVRS) is 61, indicating a moderate risk but still requires attention. This Gym Management System vulnerability allows attackers to potentially access, modify, or delete sensitive data within the application's database. Due to the publicly available exploit and the 'In The Wild' tag, the risk of exploitation is elevated. Although the SVRS isn't above 80, the vulnerability is still a significant concern because successful exploitation leads to data breaches and potential system compromise. Immediate action is necessary to apply the relevant patches or mitigations to prevent unauthorized access and maintain data integrity. The presence of CWE-89 further emphasizes the prevalence and severity of SQL Injection risks.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.