Overview
- Description
- A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument user_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is distributed under two entirely different names.
- Source
- cna@vuldb.com
- NVD status
- Analyzed
Risk scores
CVSS 4.0
- Type
- Secondary
- Base score
- 6.9
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Social media
- Hype score
- Not currently trending
CVE-2024-10758 Critical SQL Injection Vulnerability in Content Management System and News-Buzz A critical vulnerability exists in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This issu... https://t.co/xoZL9EUQLs
@VulmonFeeds
4 Nov 2024
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-10758 A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part … https://t.co/ySOzOLnYn4
@CVEnew
4 Nov 2024
682 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2024-10758: Critical SQL injection in code-projects/anirbandutta9 CMS & News-Buzz 1.0. Remote exploit available. Urgent action: Patch systems & scrutinize input validation. Assess wider impact across orgs using the software. #SQLi #InfoSec
@oktsec
3 Nov 2024
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A new vulnerability with increased severity was disclosed for code-projects and anirbandutta9 Content Management System and News-Buzz (CVE-2024-10758) https://t.co/8mJKamhLMu
@vuldb
3 Nov 2024
95 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:anirbandutta9:news-buzz:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4808771E-72B7-43EF-853F-B3080E9B519B" }, { "criteria": "cpe:2.3:a:code-projects:content_management_system:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "02CCDB18-7E64-4F10-9D59-7781D4806075" } ], "operator": "OR" } ] } ]