CVE-2024-6728
Angeljudesuarez
CVE-2024-6728 is a critical SQL Injection vulnerability in itsourcecode Tailoring Management System 1.0, allowing remote attackers to execute arbitrary SQL commands. The vulnerability exists in the file typeedit.php, specifically when manipulating the 'id' argument. Although the CVSS score is 9.8, the SOCRadar Vulnerability Risk Score (SVRS) is 65, indicating a moderate risk level, even if it does not require immediate action. This remote code execution flaw allows attackers to read, modify, or delete sensitive data, potentially compromising the entire system. The exploit is publicly available, increasing the likelihood of exploitation. Organizations using Tailoring Management System 1.0 should immediately patch their systems to mitigate this critical threat. The database could be compromised.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.