VulnerabilityModified
CVE-2024-6013
A vulnerability was found in itsourcecode Online Book Store 1.0.
MEDIUM 5.3EPSS 0.50%
Does this matter?
Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in itsourcecode Online Book Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_delete.php. The manipulation of the argument bookisbn leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268721 was assigned to this vulnerability.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.50% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- itsourcecode/online book store project in php and mysql with source code
- Source
- cna@vuldb.com
References
- https://github.com/gabriel202212/cve/issues/1Exploit, Technical Description, Third Party Advisory
- https://vuldb.com/?ctiid.268721Permissions Required
- https://vuldb.com/?id.268721Third Party Advisory
- https://vuldb.com/?submit.357075Issue Tracking
- https://github.com/gabriel202212/cve/issues/1Exploit, Technical Description, Third Party Advisory
- https://vuldb.com/?ctiid.268721Permissions Required
- https://vuldb.com/?id.268721Third Party Advisory
- https://vuldb.com/?submit.357075Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.