Campcodes House Rental Management System manage_tenant.php sql injection
Published Apr 12, 2024
8.8
HIGHCVSS 3.1
EPSS 0.68%
Description
A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected is an unknown function of the file manage_tenant.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260484.
Affected products
-
Affected
- 1.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Campcodes | House Rental Management System | unknown | Affected
|
- 1.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-32272 Advisory
- https://github.com/E1CHO/cve_hub/blob/main/House%20Rental%20Management%20System/House%20Rental%20Management%20System%20-%20vuln%203.pdf exploit
- https://vuldb.com/?ctiid.260484 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.260484 vdb-entrytechnical-descriptionPermissions RequiredVDB Entry
- https://vuldb.com/?submit.314203 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-32272 | Advisory | |
| https://github.com/E1CHO/cve_hub/blob/main/House%20Rental%20Management%20System/House%20Rental%20Management%20System%20-%20vuln%203.pdf | exploit | |
| https://vuldb.com/?ctiid.260484 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.260484 | vdb-entrytechnical-descriptionPermissions RequiredVDB Entry | |
| https://vuldb.com/?submit.314203 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data