CVE-2024-3001
Last modified
CVE-2024-3001 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability, which was classified as critical, has been found in code-projects Online Book System 1.0. This issue affects some unknown processing of the file /Product.php. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
A vulnerability, which was classified as critical, has been found in code-projects Online Book System 1.0. This issue affects some unknown processing of the file /Product.php. The manipulation of the argument value leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258203.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Anisha | Online Book System | 1.0 |
References
- https://vuldb.com/?ctiid.258203Permissions Required, VDB Entry
- https://vuldb.com/?id.258203Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.305055Third Party Advisory, VDB Entry
- https://vuldb.com/?ctiid.258203Permissions Required, VDB Entry
- https://vuldb.com/?id.258203Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.305055Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-3001?
How severe is CVE-2024-3001?
How do I fix CVE-2024-3001?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-30004Windows Mobile Broadband Driver Remote Code Execution Vulner…6.8
- CVE-2024-30005Windows Mobile Broadband Driver Remote Code Execution Vulner…6.8
- CVE-2024-30006Microsoft WDAC OLE DB provider for SQL Server Remote Code Ex…8.8
- CVE-2024-30007Microsoft Brokering File System Elevation of Privilege Vulne…8.8
- CVE-2024-30008Windows DWM Core Library Information Disclosure Vulnerabili…5.5
- CVE-2024-30009Windows Routing and Remote Access Service (RRAS) Remote Code…8.8
- CVE-2024-30010Windows Hyper-V Remote Code Execution Vulnerability8.8
- CVE-2024-30011Windows Hyper-V Denial of Service Vulnerability6.5
- CVE-2024-30012Windows Mobile Broadband Driver Remote Code Execution Vulner…6.8
- CVE-2024-30013Windows MultiPoint Services Remote Code Execution Vulnerabil…8.8
- CVE-2024-30014Windows Routing and Remote Access Service (RRAS) Remote Code…7.5
- CVE-2024-30015Windows Routing and Remote Access Service (RRAS) Remote Code…7.5
Are you affected by CVE-2024-3001?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
