github.com
https://github.com/CveSecLook/cve/issues/17 CVE-2024-33485
CRITICAL
CASAP Automated Enrollment System 1.0 - Authentication Bypass
Record summary
CVE-2024-33485 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 15, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
casap_automated_enrollment_systemBrowse casap_automated_enrollment_system_project / casap_automated_enrollment_systemDefault status: unknown | CVE List | 1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCASAP Automated Enrollment System 1.0 - Authentication BypassExploitDB exploitby Himanshu ShuklaNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-33485 exploit-db.com
https://www.exploit-db.com/exploits/49463