Severity
5.3MEDIUMNVD
EPSS
0.1%
top 74.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 15
Latest updateNov 6

Description

A vulnerability classified as critical has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=delete_product. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

🔴Vulnerability Details

2
GHSA
GHSA-g773-pwrm-8hmq: A vulnerability classified as critical has been found in SourceCodester Simple Online Bidding System 12024-08-15
CVEList
SourceCodester Simple Online Bidding System ajax.php sql injection2024-08-14

📋Vendor Advisories

3
Cisco
Cisco 7800, 8800, and 9800 Series Phones Information Disclosure Vulnerability2024-11-06
Cisco
Cisco 6800, 7800, 8800, and 9800 Series Phones with Multiplatform Firmware Stored Cross-Site Scripting Vulnerabilities2024-11-06
Cisco
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Vulnerabilities2024-05-01
CVE-2024-7800 — SQL Injection | cvebase