SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive information via a crafted payload to the kortex_lite/control/register_case.php interface
References
Link | Resource |
---|---|
https://blog.csdn.net/samwbs/article/details/140954482 | Exploit Third Party Advisory |
https://github.com/samwbs/kortexcve/blob/main/xss_register_case/XSS_register_case.md | Not Applicable |
Configurations
History
19 Sep 2024, 01:38
Type | Values Removed | Values Added |
---|---|---|
First Time |
Mayurik
Mayurik best Free Law Office Management |
|
CWE | CWE-89 | |
CPE | cpe:2.3:a:mayurik:best_free_law_office_management:1.0:*:*:*:*:*:*:* | |
References | () https://blog.csdn.net/samwbs/article/details/140954482 - Exploit, Third Party Advisory | |
References | () https://github.com/samwbs/kortexcve/blob/main/xss_register_case/XSS_register_case.md - Not Applicable |
16 Sep 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-94 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
Summary |
|
13 Sep 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-13 20:15
Updated : 2024-09-19 01:38
NVD link : CVE-2024-44430
Mitre link : CVE-2024-44430
CVE.ORG link : CVE-2024-44430
JSON object : View
Products Affected
mayurik
- best_free_law_office_management