216.73.217.55

CVE-2024-51327

· Published 04/11/2024 18:15 · Modified 06/11/2024 15:02

Labels: CVE-2024-51327 2024-11-04CVE-2024-51327CWE-89[email protected]

Essential information

Published
04/11/2024 18:15
Modified
06/11/2024 15:02
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL Injection in the 'username' and 'password' fields.

NVD status

Status
Analyzed — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
projectworlds / travel management system cpe:2.3:a:projectworlds:travel_management_system:1.0:*:*:*:*:*:*:*

References