CVE-2024-37872

HIGH

Itsourcecode Billing System in PHP 1.0 - SQL Injection via Username Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in process.php in Itsourcecode Billing System in PHP 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory
https://github.com/TThuyyy/cve1/issues/4

Scores

CVSS v3 8.1
EPSS 0.0008
EPSS Percentile 23.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
angeljudesuarez/billing_system 1.0
Published Jul 09, 2024
Tracked Since Feb 18, 2026