Skip to main content

CVE-2024-1971

7.3
HIGHCVSS v3.1 Base Score
0.07%
LOW RiskEPSS (22nd percentile)

A vulnerability has been found in Surya2Developer Online Shopping System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Parameter Handler. The manipulation of the argument password with the input nochizplz'+or+1%3d1+limit+1%23 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-255127.

Published: 2/29/2024
Modified: 12/17/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.3HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS Score (Exploitation Probability)

0.07%LOW Exploitation Risk
22nd percentile

This vulnerability has a 0.07% probability of being exploited in the next 30 days, ranking higher than 22% of all scored CVEs.

Related Vulnerabilities