CVE-2024-7936
20.08.2024, 00:15
A vulnerability classified as critical has been found in itsourcecode Project Expense Monitoring System 1.0. This affects an unknown part of the file transferred_report.php. The manipulation of the argument start/end/employee leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Vendor | Product | Version |
---|---|---|
project_expense_monitoring_system_project | project_expense_monitoring_system | 1.0 |
𝑥
= Vulnerable software versions