CVE-2024-10136
published 2024-10-19CVE-2024-10136: A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.53%
41.0th percentile
A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_invoice.php. The manipulation of the argument invoice_number leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | pharmacy_management_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pj59-59fw-j7px: A vulnerability was found in code-projects Pharmacy Management System 1
ghsa_unreviewed·2024-10-19
CVE-2024-10136 [MEDIUM] CWE-89 GHSA-pj59-59fw-j7px: A vulnerability was found in code-projects Pharmacy Management System 1
A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_invoice.php. The manipulation of the argument invoice_number leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Red Hat
networkmanager: GRE & GRE6 protocol excessive trust
vendor_redhat·2025-01-14·CVSS 5.3
CVE-2024-7595 [MEDIUM] CWE-348 networkmanager: GRE & GRE6 protocol excessive trust
networkmanager: GRE & GRE6 protocol excessive trust
GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.
This can be considered similar to CVE-2020-10136.
An insecure configuration flaw was found in the GRE and GRE6 Protocols. When configured to not require authentication or filtering, this issue could allow a remote unauthenticated attacker to spoof packets or bypass access controls.
Statement: This vulnerability is rated as Low impact as it requires a known higher risk configuration. Multiple layers of defaults (packet forwarding and these specific protocols) are disable
Red Hat
networkmanager: UDP encapsulation protocol excessive trust
vendor_redhat·2025-01-14·CVSS 5.3
CVE-2024-7596 [MEDIUM] CWE-348 networkmanager: UDP encapsulation protocol excessive trust
networkmanager: UDP encapsulation protocol excessive trust
Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.
This can be considered similar to CVE-2020-10136.
An insecure configuration flaw was found in the Generic UDP Encapsulation Protocol. When configured to not require authentication or filtering, this issue could allow a remote unauthenticated attacker to spoof packets or bypass access controls.
Statement: This vulnerability is rated as Low impact as it requires a known higher risk configuration. Multiple layers of defaults (packet forwarding a
Red Hat
kernel: drm/lima: mask irqs in timeout path before hard reset
vendor_redhat·2024-07-12·CVSS 5.5
CVE-2024-40976 [MEDIUM] kernel: drm/lima: mask irqs in timeout path before hard reset
kernel: drm/lima: mask irqs in timeout path before hard reset
In the Linux kernel, the following vulnerability has been resolved:
drm/lima: mask irqs in timeout path before hard reset
There is a race condition in which a rendering job might take just long
enough to trigger the drm sched job timeout handler but also still
complete before the hard reset is done by the timeout handler.
This runs into race conditions not expected by the timeout handler.
In some very specific cases it currently may result in a refcount
imbalance on lima_pm_idle, with a stack dump such as:
[10136.669170] WARNING: CPU: 0 PID: 0 at drivers/gpu/drm/lima/lima_devfreq.c:205 lima_devfreq_record_idle+0xa0/0xb0
...
[10136.669459] pc : lima_devfreq_record_idle+0xa0/0xb0
...
[10136.669628] Call trace:
[10136.669634] lima
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-7595 networkmanager: GRE & GRE6 protocol excessive trust
bugzilla·2024-10-08·CVSS 5.3
CVE-2024-7595 [MEDIUM] CVE-2024-7595 networkmanager: GRE & GRE6 protocol excessive trust
CVE-2024-7595 networkmanager: GRE & GRE6 protocol excessive trust
GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.
Bugzilla
CVE-2024-7596 networkmanager: UDP encapsulation protocol excessive trust
bugzilla·2024-10-08·CVSS 5.3
CVE-2024-7596 [MEDIUM] CVE-2024-7596 networkmanager: UDP encapsulation protocol excessive trust
CVE-2024-7596 networkmanager: UDP encapsulation protocol excessive trust
Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.
2024-10-19
Published