Vulnerability Description
A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument user_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is distributed under two entirely different names.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Anirbandutta9 | News-Buzz | 1.0 |
| Code-Projects | Content Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/EmilGallajov/zero-day/blob/main/content_management_system_sqlExploitThird Party Advisory
- https://vuldb.com/?ctiid.282927Permissions RequiredVDB Entry
- https://vuldb.com/?id.282927Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.436395Third Party AdvisoryVDB Entry
FAQ
What is CVE-2024-10758?
CVE-2024-10758 is a vulnerability with a CVSS score of 7.3 (HIGH). A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file /index.php. The manipu...
How severe is CVE-2024-10758?
CVE-2024-10758 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-10758?
Check the references section above for vendor advisories and patch information. Affected products include: Anirbandutta9 News-Buzz, Code-Projects Content Management System.