Vulnerability Description
A vulnerability has been found in Project Worlds Student Project Allocation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /student/project_selection/remove_project.php of the component Project Selection Page. The manipulation of the argument no leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Projectworlds | Student Project Allocation System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/jadu101/CVE/blob/main/phpgurukul_student_project_allocation_sExploitThird Party Advisory
- https://vuldb.com/?ctiid.281965Permissions RequiredVDB Entry
- https://vuldb.com/?id.281965Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.431983Third Party AdvisoryVDB Entry
FAQ
What is CVE-2024-10424?
CVE-2024-10424 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability has been found in Project Worlds Student Project Allocation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /student/proje...
How severe is CVE-2024-10424?
CVE-2024-10424 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-10424?
Check the references section above for vendor advisories and patch information. Affected products include: Projectworlds Student Project Allocation System.