PT-2024-16583 · Unknown · Romadebrian Web-Sekolah

·

CVE-2024-10841

·

Published

2024-11-05

·

Updated

2024-11-09

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions romadebrian WEB-Sekolah version 1.0
Description A critical vulnerability was found in the Mail Handler component of romadebrian WEB-Sekolah. The manipulation of the Name argument in the /Proses Kirim.php file leads to SQL injection. The attack can be launched remotely. Other parameters might be affected as well.
Recommendations For romadebrian WEB-Sekolah version 1.0, update to the latest version and apply all recommended patches to safeguard your systems. As a temporary workaround, consider restricting access to the /Proses Kirim.php file and the Name argument to minimize the risk of exploitation.

Exploit

Fix

Improper Neutralization

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10841

Affected Products

Romadebrian Web-Sekolah