CVE-2024-7455

MEDIUM

Tailoring Management System 1.0 - SQL Injection via partedit.php id Parameter

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file partedit.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273549 was assigned to this vulnerability.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.273549
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.273549
Technical Description, VDB Entry third-party-advisory
https://vuldb.com/?submit.385442
Exploit, Technical Description, Third Party Advisory exploit issue-tracking
https://github.com/Wumshi/cve/issues/3

Scores

CVSS v3 6.3
EPSS 0.0009
EPSS Percentile 24.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
angeljudesuarez/tailoring_management_system_project_in_php 1.0
Published Aug 04, 2024
Tracked Since Feb 18, 2026