CVE-2024-44430

CRITICAL

Best Free Law Office Management Software 1.0 - SQL Injection via kortex_lite/control/register_case.php

Title source: llm
STIX 2.1

Description

SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive information via a crafted payload to the kortex_lite/control/register_case.php interface

Scores

CVSS v3 9.8
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-94 CWE-89
Status published
Products (1)
mayurik/best_free_law_office_management 1.0
Published Sep 13, 2024
Tracked Since Feb 18, 2026