Vulnerability CVE-2024-28322


Published: 2024-04-26   Modified: 2024-04-27

Description:
SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST request.

 References:
https://github.com/Sospiro014/zday1/blob/main/event-managment.md
https://packetstormsecurity.com/files/177841/Event-Management-1.0-SQL-Injection.html

Copyright 2024, cxsecurity.com

 

Back to Top