216.73.216.226

CVE-2024-9086

· Published 22/09/2024 21:15 · Modified 26/09/2024 15:26

Labels: CVE-2024-9086 2024-09-22CVE-2024-9086CWE-89[email protected]

Essential information

Published
22/09/2024 21:15
Modified
26/09/2024 15:26
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. Affected is an unknown function of the file /filter.php. The manipulation of the argument from/to leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "from" to be affected. But it must be assumed that parameter "to" is affected as well.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
code-projects / restaurant reservation system cpe:2.3:a:code-projects:restaurant_reservation_system:1.0:*:*:*:*:*:*:*

References