github.com
https://github.com/kaliankhe/CVE-Aslam-mahi/blob/9ec0572c68bfd3708a7d6e089181024131f4e927/vendors/projectworlds.in/AEGON%20LIFE%20v1.0%20Life%20Insurance%20Management%20System/CVE-2024-36597 CVE-2024-36597
HIGH
AEGON LIFE v1.0 Life Insurance Management System - SQL injection vulnerability.
Record summary
CVE-2024-36597 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 17, 2024 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBAEGON LIFE v1.0 Life Insurance Management System - SQL injection vulnerability.ExploitDB exploitby Aslam Anwar MahimkarNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-36597 exploit-db.com
https://www.exploit-db.com/exploits/52046