ZeroHour

CVE-2024-40486

PoC
CVSS 3.1
9.8 critical
EPSS
1%p61
Published
()
Modified
Description

A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters.

Vendors
lopalopa
Products
live membership system
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.