Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33106 | A vulnerability has been found in Project Worlds Student Project Allocation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /student/project_selection/remove_project.php of the component Project Selection Page. The manipulation of the argument no leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 29 Oct 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:projectworlds:student_project_allocation_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Yugeshverma
Yugeshverma student Project Allocation System |
Tue, 29 Oct 2024 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yugeshverma
Yugeshverma student Project Allocation System |
|
| CPEs | cpe:2.3:a:yugeshverma:student_project_allocation_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Yugeshverma
Yugeshverma student Project Allocation System |
Mon, 28 Oct 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Projectworlds
Projectworlds student Project Allocation System |
|
| CPEs | cpe:2.3:a:projectworlds:student_project_allocation_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Projectworlds
Projectworlds student Project Allocation System |
|
| Metrics |
ssvc
|
Sun, 27 Oct 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in Project Worlds Student Project Allocation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /student/project_selection/remove_project.php of the component Project Selection Page. The manipulation of the argument no leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | Project Worlds Student Project Allocation System Project Selection Page remove_project.php sql injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-10-28T13:11:20.421Z
Reserved: 2024-10-26T14:07:13.732Z
Link: CVE-2024-10424
Updated: 2024-10-28T13:11:14.770Z
Status : Analyzed
Published: 2024-10-27T19:15:04.273
Modified: 2024-10-29T13:11:42.527
Link: CVE-2024-10424
No data.
OpenCVE Enrichment
No data.
EUVD