CVE-2024-3620

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
11/04/2024
Last modified:
28/01/2025

Description

A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /control/adds.php. The manipulation of the argument name/gender/dob/email/mobile/address leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260276.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mayurik:advocate_office_management_system:1.0:*:*:*:*:*:*:*